Also known as: SOURGUM, Candiru
Caramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting specific victims through watering hole attacks. Candiru has been observed exploiting vulnerabilities in popular browsers like Google Chrome and using third-party signed drivers to gain access to the Windows kernel. They have also been linked to other spyware vendors and have been associated with extensive abuses of their surveillance tools.
Executive Summary
Caramel Tsunami, also known as SOURGUM or Candiru, is a threat actor reemerging with updated toolsets and zero-day exploits. Known for sophisticated spyware attacks, they primarily target specific sectors through advanced tactics such as watering hole attacks and browser exploitation. Their activities pose significant risks to targeted organizations, particularly in regions like the Middle East and North Africa.
Goals & Targeting
Caramel Tsunami's primary goal appears to be intelligence collection and surveillance, likely for espionage purposes. Their targeting focuses on sectors that would yield sensitive information, such as government agencies, defense contractors, and financial institutions. The group has demonstrated a preference for specific regions, including the Middle East and North Africa, possibly due to geopolitical interests or operational ease. Its victims are typically selected based on their ability to provide actionable intelligence or disrupt critical operations.
Enhanced Description
Caramel Tsunami is a cyber threat actor with a focus on espionage and surveillance activities. The group has recently reemerged with enhanced capabilities, including zero-day exploits and improved toolsets, targeting specific victims through watering hole attacks. They are known for exploiting vulnerabilities in popular browsers like Google Chrome, leveraging third-party signed drivers to achieve kernel-level access on Windows systems. This level of technical proficiency indicates a high degree of sophistication in their attack methods. The group has also been linked to other spyware vendors, suggesting potential collaboration or shared toolsets. Their activities include extensive abuse of surveillance tools, likely for intelligence gathering or espionage purposes. Caramel Tsunami's operations highlight a strategic approach to targeting, focusing on specific sectors and regions where they can achieve maximum impact.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Caramel Tsunami's campaigns are characterized by their precision and technical depth. They appear to operate with a measured operational tempo, focusing on high-value targets rather than broad campaigns. Notable past operations include targeting financial institutions and government agencies in the Middle East, where they have demonstrated persistence and lateral movement within networks. The group's ability to exploit unpatched vulnerabilities underscores their capability for strategic, long-term operations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Caramel Tsunami's details is moderate, as the group's operational methods and motivations are partially understood. While their toolset aligns with advanced persistent threat actors, gaps exist in understanding their long-term strategic goals and geographic focus outside of known campaigns. Additional data on their infrastructure and victimology would improve situational awareness.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics