Beautiful Virgin Islands

Wednesday, Dec 10, 2025

Israeli firm’s spyware linked to attacks on websites in UK and Middle East

Israeli firm’s spyware linked to attacks on websites in UK and Middle East

Canada-based researchers say new evidence suggests Candiru’s software used to target critics of autocratic regimes
Researchers have found new evidence that suggests spyware made by an Israeli company that was recently blacklisted in the US has been used to target critics of Saudi Arabia and other autocratic regimes, including some readers of a London-based news website.

A report by Montreal-based researchers from Slovakian company Eset, an internet security firm, found links between attacks against high-profile websites in the Middle East and UK, and the Israeli company Candiru, which has been called Israel’s “most mysterious cyberwarfare company”.

Candiru and NSO Group, a much more prominent Israeli surveillance company, were both added to a US blacklist this month after the Biden administration took the rare step of accusing the firms of acting against US national security interests.

The Eset report revealed new information about so-called “watering hole attacks”. In such attacks, spyware users launch malware against ordinary websites that are known to attract readers or users who are considered “targets of interest” by the user of the malware.

The sophisticated attacks allow the malware user to identify characteristics about the individuals who have visited the website, including what kind of browser and operating system they are using. In some cases the malware user can then launch an exploit that allows them to take over an individual target’s computer.

Unlike NSO Group’s signature spyware, which is called Pegasus and infects mobile phones, Candiru’s malware is believed by researchers to infect computers. The company appears to be named after a parasitic freshwater catfish that can be found in the Amazon.

The researchers found that the websites that were “known targets” of this kind of attack included Middle East Eye, a London-based news website, and multiple websites associated with government ministries in Iran and Yemen.

Candiru did not respond to the Guardian’s request for comment.

Middle East Eye condemned the attacks. In a statement, its editor-in-chief, David Hearst, said the outlet was no stranger to attempts to take the website down by state and non-state actors.

“Substantial sums of money have been spent trying to take us out. This has not stopped us reporting what is going on in all corners of the region and I am confident that they will not stop us in future,” he said.

Once websites are compromised, researchers at Eset say, they are considered “jumping off sites” that help malware users target individuals. In other words, not every individual who visited one of the compromised websites would have been in danger of being hacked, but users of the malware are believed to have used the websites as a starting point to help identify a much smaller group of individuals who were then targeted.

Matthieu Faou, who uncovered the campaigns, said Eset developed a custom in-house system in 2018 to uncover “watering holes” on high-profile websites. In July 2020, the system notified them that an Iranian embassy website in Abu Dhabi had been tainted with malicious code.

“Our curiosity was aroused by the high-profile nature of the targeted website, and in the following weeks we noticed that other websites with connections to the Middle East were also targeted,” Faou said.

The “threat group” then “went quiet” until it resurfaced in January 2021 and was active until late summer in 2021, when all the websites that were observed to have been victims of attacks were then “cleaned”, Eset said.

Eset said it believed hacking activities ended in late July 2021 after a report by researchers at Citizen Lab, released in conjunction with Microsoft, detailed Candiru’s alleged surveillance activities. That report accused Candiru of selling spyware to governments linked to fake Black Lives Matter and Amnesty International websites that were used to hack targets.

In the July 2021 report, Citizen Lab, a research group affiliated with the University of Toronto, said the Tel Aviv-based Candiru made “untraceable” spyware that could infect computers and phones.

At the time, Candiru declined to comment.

Microsoft said in July that it appeared that Candiru sold the spyware that enabled the hacks, and that the governments generally chose who to target and ran the operations themselves. The company also announced at the time that it had disabled the “cyberweapons” of Candiru and built protections against the malware, including issuing a Windows software update.

There is little public information available about Candiru, which was founded in 2014 and has undergone several name changes. In 2017 the company was selling its malware to clients in the Gulf, western Europe and Asia, according to a lawsuit reported in an Israeli newspaper. Candiru may have deals with Uzbekistan, Saudi Arabia and the UAE, Forbes has reported.

Microsoft reported that it had found victims of the spyware in Israel and Iran. Citizen Lab said it was able to identify a computer that had been hacked by Candiru’s malware, and then used that hard drive to extract a copy of the firm’s Windows spyware. The owner of the computer was a “politically active” individual in western Europe, it said.

This month Candiru made headlines after the Biden administration announced it had added the company to the commerce department’s entity list, a blacklist usually reserved for America’s worst enemies, including Chinese and Russian hackers.

In its press release, the commerce department said it had evidence that Candiru developed and supplied spyware to foreign governments that used it to maliciously target government officials, journalists, businesspeople, activists, academics and embassy workers. The tools also helped to enable foreign governments to conduct “transnational repression”, the department said.

Candiru has not commented on its placement on the entity list.
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
UK Warns of Escalating Cyber Assault Linked to Putin’s State-Backed Operations
UK Consumer Spending Falters in November as Households Hold Back Ahead of Budget
UK Orders Fresh Review of Prince Harry’s Security Status After Formal Request
U.S. Authorises Nvidia to Sell H200 AI Chips to China Under Security Controls
Trump in Direct Assault: European Leaders Are Weak, Immigration a Disaster. Russia Is Strong and Big — and Will Win
"App recommendation" or disguised advertisement? ChatGPT Premium users are furious
"The Great Filtering": Australia Blocks Hundreds of Thousands of Minors From Social Networks
Mark Zuckerberg Pulls Back From Metaverse After $70 Billion Loss as Meta Shifts Priorities to AI
Nvidia CEO Says U.S. Data-Center Builds Take Years while China ‘Builds a Hospital in a Weekend’
Indian Airports in Turmoil as IndiGo Cancels Over a Thousand Flights, Stranding Thousands
Hollywood Industry on Edge as Netflix Secures Near-$60 Bln Loan for Warner Bros Takeover
Drugs and Assassinations: The Connection Between the Italian Mafia and Football Ultras
Hollywood megadeal: Netflix acquires Warner Bros. Discovery for 83 billion dollars
The Disregard for a Europe ‘in Danger of Erasure,’ the Shift Toward Russia: Trump’s Strategic Policy Document
Two and a Half Weeks After the Major Outage: A Cloudflare Malfunction Brings Down Multiple Sites
UK data-regulator demands urgent clarity on racial bias in police facial-recognition systems
Labour Uses Biscuits to Explain UK Debt — MPs Lean Into Social Media to Reach New Audiences
German President Lays Wreath at Coventry as UK-Germany Reaffirm Unity Against Russia’s Threat
UK Inquiry Finds Putin ‘Morally Responsible’ for 2018 Novichok Death — London Imposes Broad Sanctions on GRU
India backs down on plan to mandate government “Sanchar Saathi” app on all smartphones
King Charles Welcomes German President Steinmeier to UK in First State Visit by Berlin in 27 Years
UK Plans Major Cutback to Jury Trials as Crown Court Backlog Nears 80,000
UK Government to Significantly Limit Jury Trials in England and Wales
U.S. and U.K. Seal Drug-Pricing Deal: Britain Agrees to Pay More, U.S. Lifts Tariffs
UK Postpones Decision Yet Again on China’s Proposed Mega-Embassy in London
Head of UK Budget Watchdog Resigns After Premature Leak of Reeves’ Budget Report
Car-sharing giant Zipcar to exit UK market by end of 2025
Reports of Widespread Drone Deployment Raise Privacy and Security Questions in the UK
UK Signals Security Concerns Over China While Pursuing Stronger Trade Links
Google warns of AI “irrationality” just as Gemini 3 launch rattles markets
Top Consultancies Freeze Starting Salaries as AI Threatens ‘Pyramid’ Model
Macron Says Washington Pressuring EU to Delay Enforcement of Digital-Regulation Probes Against Meta, TikTok and X
UK’s DragonFire Laser Downs High-Speed Drones as £316m Deal Speeds Naval Deployment
UK Chancellor Rejects Claims She Misled Public on Fiscal Outlook Ahead of Budget
Starmer Defends Autumn Budget as Finance Chief Faces Accusations of Misleading Public Finances
EU Firms Struggle with 3,000-Hour Paperwork Load — While Automakers Fear De Facto 2030 Petrol Car Ban
White House launches ‘Hall of Shame’ site to publicly condemn media outlets for alleged bias
UK Budget’s New EV Mileage Tax Undercuts Case for Plug-In Hybrids
UK Government Launches National Inquiry into ‘Grooming Gangs’ After US Warning and Rising Public Outcry
Taylor Swift Extends U.K. Chart Reign as ‘The Fate of Ophelia’ Hits Six Weeks at No. 1
250 Still Missing in the Massive Fire, 94 Killed. One Day After the Disaster: Survivor Rescued on the 16th Floor
Trump: National Guard Soldier Who Was Shot in Washington Has Died; Second Soldier Fighting for His Life
UK Chancellor Reeves Defends Tax Rises as Essential to Reduce Child Poverty and Stabilise Public Finances
No Evidence Found for Claim That UK Schools Are Shifting to Teaching American English
European Powers Urge Israel to Halt West Bank Settler Violence Amid Surge in Attacks
"I Would Have Given Her a Kidney": She Lent Bezos’s Ex-Wife $1,000 — and Received Millions in Return
European States Approve First-ever Military-Grade Surveillance Network via ESA
UK to Slash Key Pension Tax Perk, Targeting High Earners Under New Budget
UK Government Announces £150 Annual Cut to Household Energy Bills Through Levy Reforms
UK Court Hears Challenge to Ban on Palestine Action as Critics Decry Heavy-Handed Measures
×