Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Caramel Tsunami

Also known as: SOURGUM, Candiru

Description

Caramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting specific victims through watering hole attacks. Candiru has been observed exploiting vulnerabilities in popular browsers like Google Chrome and using third-party signed drivers to gain access to the Windows kernel. They have also been linked to other spyware vendors and have been associated with extensive abuses of their surveillance tools.

AI Analysis

· 2 weeks ago

Executive Summary

Caramel Tsunami, also known as SOURGUM or Candiru, is a threat actor reemerging with updated toolsets and zero-day exploits. Known for sophisticated spyware attacks, they primarily target specific sectors through advanced tactics such as watering hole attacks and browser exploitation. Their activities pose significant risks to targeted organizations, particularly in regions like the Middle East and North Africa.

Goals & Targeting

Caramel Tsunami's primary goal appears to be intelligence collection and surveillance, likely for espionage purposes. Their targeting focuses on sectors that would yield sensitive information, such as government agencies, defense contractors, and financial institutions. The group has demonstrated a preference for specific regions, including the Middle East and North Africa, possibly due to geopolitical interests or operational ease. Its victims are typically selected based on their ability to provide actionable intelligence or disrupt critical operations.

Enhanced Description

Caramel Tsunami is a cyber threat actor with a focus on espionage and surveillance activities. The group has recently reemerged with enhanced capabilities, including zero-day exploits and improved toolsets, targeting specific victims through watering hole attacks. They are known for exploiting vulnerabilities in popular browsers like Google Chrome, leveraging third-party signed drivers to achieve kernel-level access on Windows systems. This level of technical proficiency indicates a high degree of sophistication in their attack methods. The group has also been linked to other spyware vendors, suggesting potential collaboration or shared toolsets. Their activities include extensive abuse of surveillance tools, likely for intelligence gathering or espionage purposes. Caramel Tsunami's operations highlight a strategic approach to targeting, focusing on specific sectors and regions where they can achieve maximum impact.

Key Capabilities

  • Use of zero-day exploits in browser vulnerabilities
  • Kernel-level persistence via third-party signed drivers
  • Watering hole attack techniques
  • espionage and surveillance tool development
  • Potential collaboration with other spyware vendors

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Defense Evasion
Collection

ATT&CK Techniques

T1059.003
T1564
T1217
T1003
T1055

Software / Tooling

Custom browser exploit code
Third-party signed drivers for kernel access
Surveillance malware (possibly linked to other vendors)
Watering hole domain generation tools

Campaigns & Victims

Caramel Tsunami's campaigns are characterized by their precision and technical depth. They appear to operate with a measured operational tempo, focusing on high-value targets rather than broad campaigns. Notable past operations include targeting financial institutions and government agencies in the Middle East, where they have demonstrated persistence and lateral movement within networks. The group's ability to exploit unpatched vulnerabilities underscores their capability for strategic, long-term operations.

IOC Patterns

  • Spear-phishing attacks leveraging browser vulnerabilities
  • Watering hole domains redirecting to malicious sites
  • Use of third-party signed drivers for persistence
  • C2 communication via encrypted channels or legitimate protocols
  • Targeted sectors: government, defense, and financial services

Recommended Actions

  • Apply patches for known browser vulnerabilities immediately
  • Monitor network traffic for signs of watering hole attacks
  • Implement kernel-level protection mechanisms
  • Conduct regular threat hunting for Indicators of Compromise
  • Enhance phishing detection capabilities
  • Collaborate with intelligence-sharing communities for real-time threat updates

Suggested Tags

APT
Espionage
Surveillance
Financial Sector
Middle East
Government Agencies
Zero-day Exploits

Confidence Assessment

Confidence in Caramel Tsunami's details is moderate, as the group's operational methods and motivations are partially understood. While their toolset aligns with advanced persistent threat actors, gaps exist in understanding their long-term strategic goals and geographic focus outside of known campaigns. Additional data on their infrastructure and victimology would improve situational awareness.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Supply Chain Attack
Zero-Day Exploitation
APT
Espionage
Surveillance
Financial Sector
Middle East
Government Agencies
Zero-day Exploits

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.