Candiru (Saito Tech Ltd)
Israeli spyware vendor registered as Saito Tech Ltd. Microsoft found its DevilsTongue software on the devices of more than 100 people in 2021, approximately half of them in Palestine. Sells only to governments, exports under Israeli Ministry of Defence licence, and was added to the US Entity List in November 2021. An American fund, Integrity Partners, bought its assets in 2025.
Take Action
Apply pressure where it matters. Use these tools and personalise your message with evidence from this page.
- Write to Buyers and RegulatorsTemplate letters for export regulators, legislators and public bodies on why this spyware must not be licensed or bought
- Report New IntelligenceSubmit export licences, procurement records, infrastructure indicators or new deployments through the encrypted form
- Share This ProfileShare on LinkedIn to reach security research, export-control and procurement professionals
- Strategic AnalysisIn-depth analysis and engagement strategy
Before taking action, review our Code of Conduct for professional standards and ethical guidelines.
Help Us Hold Candiru (Saito Tech Ltd) Accountable
Your skills and knowledge can strengthen this campaign. Join our volunteer research team or share insider information securely.
Leverage Your Expertise
Do you work in this sector? We need professionals who understand procurement cycles, regulatory compliance, and corporate governance. Don't just boycott - lead!
Decision-Maker Directory
Key individuals with influence over corporate partnerships and procurement decisions. The contact details shown are published business addresses, listed for professional correspondence only. Write to the role, not the person, and keep correspondence courteous and factual. Repeated, abusive or personal contact is unlawful harassment and damages the case being made.
Material Risk Framing
Frame your message around business risks. These talking points resonate with corporate stakeholders and institutional investors.
A Barcelona court opened an investigation on 16 September 2025 into the surveillance of Catalan independence figures. On 9 February 2026 Judge Julia Tortosa Garcia-Vaso formally named executives of Saito Tech Ltd as suspects, alongside two former directors of Spain's Guardia Civil and the former head of its intelligence service. The alleged offences are disclosure of computer secrets and illegal access to computer systems. The US Commerce Department added Candiru to the Entity List in November 2021, with a presumption of denial on licences.
Candiru is privately held and publishes no accounts. Calcalist reported in April 2025 that the American fund Integrity Partners had agreed to buy its assets for up to $30 million. It paid $10 million in a first phase to move the staff; the balance falls due once Candiru's export licences transfer to the new entity, which Israel must approve. A leaked project proposal published by TheMarker priced one deployment at EUR 16 million for ten devices monitored at once.
Citizen Lab identified more than 750 websites built to deliver Candiru's spyware, many of them impersonating Amnesty International, the Black Lives Matter movement, United Nations agencies and news outlets. Microsoft's victims were politicians, journalists, academics, embassy workers and human rights activists, approximately half of them in Palestine. ESET found a Candiru-linked watering-hole attack on the news site Middle East Eye; a company executive replied that its product 'is purposed to help law enforcement agencies to fight terror and crime'.
The business runs on software flaws that stop working once they are found. Microsoft patched two Windows vulnerabilities Candiru was exploiting in July 2021. In July 2022 Google patched a Chrome flaw used against Avast's users in Lebanon, Turkey, Yemen and Palestine; Lebanese users were reached through a compromised news agency website. Israel cut the list of countries its cyber firms may sell to from 102 to 37 in November 2021.
Strategic Analysis
In-depth assessment of the company's position, vulnerabilities, and recommended approaches for effective engagement.
High severity, high vulnerability — campaigns with the best chance of making an impact
Severity
7.0/10
(5 + 9) ÷ 2 = 7.0
Strategic Vulnerability
6.0/10
(4 + 8) ÷ 2 = 6.0
Learn about our methodology — companies are categorised based on severity (harm potential) vs strategic vulnerability (campaign leverage).
Why do these scores change?
Unlike static boycott lists, our targeting model is dynamic. This company's position on the matrix is re-evaluated continually as we verify new contracts, divestments, or policy changes. Your reporting directly impacts this score.
Candiru sells break-in software for Windows computers, and only to governments. Microsoft found more than 100 people infected with it in July 2021, approximately half of them in Palestine, more than in any other place it named. Candiru is Israeli, so every sale is a defence export needing a licence from Israel's Ministry of Defence. That is the ministry of a state whose occupation of Palestinian territory the International Court of Justice, the United Nations' principal court, found unlawful on 19 July 2024. The company is privately held, publishes no accounts and has changed its registered name four times. It can still be moved, because it depends on three things it does not control: Israeli export licences, the American fund that bought its assets in 2025, and governments willing to sign.
Key Leverage Points
- Ask Microsoft how many of the Palestinian victims it warned. Its researchers found over 100 people infected with Candiru's software in July 2021, approximately half of them in Palestine, the largest share in any place they named. Half of everyone this weapon was found on lived in one small occupied place. Ask Microsoft, through its shareholders and the press, how many of those Palestinians it notified and whether it will publish a current figure.
- Ask the United States whether the blacklist followed the assets. 7amleh, the Palestinian digital rights organisation, argues that United States lawmakers can set global regulatory standards for the sale of surveillance technology. The Commerce Department put Candiru on its Entity List in November 2021, a trade blacklist under which export licences are presumed refused. In April 2025 Calcalist reported that the American fund Integrity Partners had bought the assets and moved them, with every employee, into a new company. It paid $10 million up front, and owes the balance only once Candiru's Israeli export licences transfer. Write to the Bureau of Industry and Security; ask Integrity Partners, on the record, whether it has taken those licences.
- Take the Barcelona file to your own prosecutor. On 9 February 2026 a judge there formally placed executives of Saito Tech Ltd, Candiru's registered name, under investigation, alongside two former Guardia Civil directors and Spain's former intelligence chief. Five Catalans brought the complaint; one, Joan Matamala, was forensically confirmed by Citizen Lab as infected with Candiru. Any national prosecutor can be asked to open the equivalent file.
- Put the infrastructure map to the parliaments it points at. Recorded Future mapped eight Candiru clusters in 2025. It assessed live ones as associated with Hungary and Saudi Arabia, one as highly likely linked to a customer based in Indonesia until November 2024, and left two associated with Azerbaijan of uncertain status. Parliamentarians in each of those countries can demand the procurement record and the legal basis for any interception run through it.
Evidence Summary
Microsoft's threat researchers published on 15 July 2021, the same day as Citizen Lab, a research group at the University of Toronto. Microsoft counted over 100 victims, politicians, journalists, academics, embassy workers, human rights activists and political dissidents, and put approximately half of them in Palestine. It patched two Windows flaws the same month. Citizen Lab mapped more than 750 websites built to deliver the spyware, many of them impersonating Amnesty International, the Black Lives Matter movement and United Nations agencies. The person who clicked a link about human rights was the person infected. Once installed, the software reads files and browser passwords and pulls messages out of Signal (sources).
A year later the pattern repeated. Avast reported in July 2022 that Candiru was exploiting a flaw in Google Chrome against users in Lebanon, Turkey, Yemen and Palestine, after compromising a website used by staff at a Lebanese news agency. In between, Israel's Ministry of Defence cut the list of countries to which Israeli firms may export offensive cyber tools from 102 to 37, dropping Saudi Arabia and the United Arab Emirates. Every Candiru sale is licensed against that list, so the Israeli state, not the company, decides who may buy.
The business has been registered under five names since 2014, most recently as Saito Tech Ltd. In April 2025 Calcalist reported that Integrity Partners had bought the assets for up to $30 million and moved every employee into an entity "not subject to U.S. government sanctions". Recorded Future identified it as Integrity Labs Ltd and, in August 2025, mapped eight infrastructure clusters still delivering the same spyware. Spain is where this first reached a court, on a complaint brought by five Catalans (timeline).
Engagement Strategy
Candiru sells nothing to the public. Every route runs through a regulator, a buyer, or the fund that now owns the assets (letter templates).
- Export regulators. The US Commerce Department decides whether the Entity List designation reaches the successor company; Israel's Ministry of Defence decides whether the export licences transfer. Both decisions are live.
- Legislators. Ask for a hearing on whether a blacklisted spyware business can be restructured out of its designation, and for the answer in writing.
- Public buyers. Ask any police force, ministry or oversight body whether it holds a contract with Candiru, Saito Tech Ltd or Integrity Labs Ltd. A refusal to answer is itself on the record.
- Technology companies. Microsoft and Google keep finding this software and closing the holes it uses. Ask them to publish what they find, and to say how many victims they notified.
Evidence & Sources
Verified sources including NGO reports, regulatory filings, and primary documents. Use these to substantiate your correspondence. Entries marked First-hand were reported directly to this site and are published without identifying the source.
Judge Julia Tortosa Garcia-Vaso, of Barcelona's Court of Instruction Number 2, formally named as investigated persons the former Guardia Civil directors Felix Vicente Azon and Maria Gamez, and the former CNI director Paz Esteban, together with executives of NSO Group and of Saito Tech Ltd - the first time executives of Candiru's company have been investigated in Spain. The alleged offences are 'delitos de descubrimiento y revelacion de secretos informaticos y de acceso ilegal a sistemas informaticos'. The five complainants, organised as the Sentinel Alliance, describe 78 attacks over two years from 2019. The proceedings are at the investigation stage, and no ruling had been published as of 8 August 2026.
Open sourceA Barcelona court accepted a criminal complaint on 16 September 2025 and opened an investigation phase. Those to be investigated include the former CNI director Paz Esteban, the former Guardia Civil directors Felix Vicente Azon Vilas and Maria Gamez Gamez, the NSO Group directors Shalev Hulio and Omri Lavie, and Isaac Zack as a director of Saito Tech Ltd. The complaint was brought by five businessmen and technology developers coordinated by the Sentinel Alliance victims' association, whose phones were infected 'between 2017 and 2020 on several occasions'. The report states this is the first case explicitly asking the courts to investigate the use of Candiru.
Open sourceAggregated account of the ARA report of the same date, recording that Judge Miriam de Rosa Palacio admitted the complaint and found the acts 'could constitute crimes of discovery and disclosure of computer secrets and illegal access to computer systems'. The plaintiffs are seeking declassification of documents by Spain's Council of Ministers, the formal designation of the company directors as investigated persons, and international cooperation - European Investigation Orders to Luxembourg and letters rogatory to Israel - to obtain company documentation and testimony.
Open sourceThe Commission concluded on reasonable grounds that Israeli authorities and security forces have committed and are continuing to commit acts of genocide against Palestinians in the Gaza Strip, and that the State of Israel bears responsibility for the failure to prevent genocide, its commission, and the failure to punish it. The analysis covers Gaza over the period 7 October 2023 to 31 July 2025.
Open sourceInfrastructure research with an analysis cut-off of 26 June 2025. 'Eight distinct clusters were identified. Five are assessed as highly likely to be currently active, including ones associated with Hungary and Saudi Arabia. One cluster, highly likely linked to a customer based in Indonesia, was active until November 2024, while two others, associated with Azerbaijan, remain of uncertain status.' It records that historic targets 'included politicians, human rights defenders, journalists, academics, embassy staff, and political dissidents', and repeats Microsoft's finding that approximately half of the observed victims were in Palestine. DevilsTongue can steal credentials from browsers, read Signal messages and use stolen cookies to impersonate victims on Facebook, Gmail and VK. It identifies Integrity Labs Ltd, incorporated in Israel on 18 December 2024 and directed by Naftali (Elad) Yoran, as the entity to which Candiru's assets were moved.
Open sourceReporting on the Insikt Group findings. Quotes researcher Julian-Ferdinand Vogele that the spyware can theoretically be delivered through malicious links, weaponised files, man-in-the-middle attacks and physical access to a device. Records that Integrity Partners transferred the assets to Integrity Labs Ltd, and that Integrity Partners did not respond to questions.
Open sourceThe Israeli business paper reports that the American investment fund Integrity Partners agreed to buy Candiru's operations for up to $30 million. 'The fund purchased Candiru's assets and transferred them - along with all of the company's employees - to a new entity that is not subject to U.S. government sanctions.' A first phase of $10 million, covering the employee transition, had been completed; the second phase depends on approval of the transfer of Candiru's export licences, which for an Israeli company means the Ministry of Defence. Names Isaac Zack as chairman and largest shareholder, Yaakov Weizmann and Eran Shorer as the 2014 founders, and Elad Yoran as the Integrity Partners partner leading the deal.
Open sourceThe International Court of Justice, the principal judicial organ of the United Nations, found Israel's continued presence in the occupied Palestinian territory unlawful and set out the obligations of states and the consequences for economic and trade dealings that entrench it. This is the framework within which an Israeli company whose every export is licensed by Israel's Ministry of Defence is assessed on this site.
Open source7amleh's report on the industry as a whole, assessing spyware, social media monitoring and biometric surveillance. It finds that the unchecked proliferation of these technologies in the occupied Palestinian territory 'has a repressive impact on the lives of civilians living under military occupation', and that Israeli firms market systems abroad on the strength of their use there. Its recommendations include 'ending mass surveillance of innocent civilians', accountability mechanisms 'for the use, development and production of automated surveillance technologies', and 'a comprehensive global framework to regulate the sale and transfer of these systems'.
Open sourceAvast's threat research team reported that Candiru had returned with a Chrome zero-day, CVE-2022-2294, used to attack Avast users 'in Lebanon, Turkey, Yemen, and Palestine via watering hole attacks'. In Lebanon the attackers compromised a website used by employees of a news agency. The chain ended in DevilsTongue, described as 'a full-blown spyware' which then attempted to reach the Windows kernel through a second zero-day. Avast reported the flaw to Google on 1 July 2022 and it was fixed in Chrome on 4 July. This is the second independent finding of Palestinian targeting, a year after Microsoft's.
Open sourcePosition paper by 7amleh, the Arab Center for the Advancement of Social Media, a Palestinian digital rights organisation. It traces how United States policy, capital and corporate practice shaped Israel's surveillance industry between 2002 and 2022, and argues that US lawmakers can set global regulatory standards for the sale of surveillance technology. Written by Sophia Goodfriend. Cited here as an instance of a Palestinian organisation directing its ask at the government that holds the most effective regulatory lever over this sector.
Open sourceForensic investigation identifying 'at least 65 individuals targeted or infected with mercenary spyware', of whom four were targeted with Candiru: Joan Matamala, whose infection was forensically confirmed, and Elies Campo, Xavier Vives and Pau Escrich, targeted by email. At least two were targeted with both Pegasus and Candiru. Almost all incidents occurred between 2017 and 2020. Citizen Lab does not conclusively attribute the targeting to a specific government, while noting strong circumstantial evidence of a nexus with Spanish authorities. Joan Matamala is one of the five complainants in the Barcelona criminal case.
Open sourceThree weeks after the Entity List designation, Israel's Ministry of Defence cut the list of countries to which Israeli firms may export offensive cyber tools from 102 to 37, dropping Morocco, Mexico, Saudi Arabia and the United Arab Emirates. The remaining list is largely North America, western Europe, India, Japan, South Korea and Australia. This establishes that the Israeli state, not the company, decides which governments may buy - and that it can and does change that list.
Open sourceESET documented two waves of watering-hole attacks, April to July 2020 and January to August 2021, on 21 websites belonging to media outlets in the United Kingdom, Yemen and Saudi Arabia, government institutions in Iran, Syria and Yemen, internet service providers in Yemen and Syria, and aerospace companies in Italy and South Africa. ESET describes 'strong links' to Candiru and a significant likelihood that the operators were Candiru customers, stopping short of definitive attribution. Activity stopped at the end of July 2021, days after the Citizen Lab, Google and Microsoft publications.
Open sourceReports ESET's finding that Middle East Eye's own website was used to deliver the attack over two days in April 2020. Contains one of the very few recorded Candiru responses to press questions: an executive said the company's product 'is purposed to help law enforcement agencies to fight terror and crime', that the company does not hack websites, and that its 'licence and the law' prohibit it from operating the product itself. An employee first denied knowledge of the incident and then declined to comment.
Open sourceThe Bureau of Industry and Security announced the addition of 'Candiru (Israel)' to the Entity List by final rule, on evidence that it 'developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers'. The licence review policy is a presumption of denial. The rule was published in the Federal Register on 4 November 2021 as 'Addition of Certain Entities to the Entity List' (2021-24123). Candiru is listed with seven aliases, among them Candiru Ltd and DF Associates.
Open sourceThe strongest single source on this company's Palestinian victims. Microsoft's Threat Intelligence Center states it 'has identified over 100 victims of SOURGUM's malware' and that 'approximately half of the victims were found in Palestinian Authority, with most of the remaining victims located in Israel, Iran, Lebanon, Yemen, Spain (Catalonia), United Kingdom, Turkey, Armenia, and Singapore'. The victims were 'politicians, human rights activists, journalists, academics, embassy workers, and political dissidents'. Microsoft patched two Windows privilege-escalation flaws, CVE-2021-31979 and CVE-2021-33771, in its July 2021 security updates. Microsoft names the actor SOURGUM and records that 'Citizen Lab asserts with high confidence that SOURGUM is an Israeli company commonly known as Candiru'.
Open sourceThe companion investigation by Citizen Lab at the University of Toronto, published the same day as Microsoft's. It identified 'more than 750 websites linked to Candiru's spyware infrastructure', many impersonating Amnesty International, the Black Lives Matter movement, United Nations agencies and news organisations. It records the sequence of company names - Candiru Ltd (2014), DF Associates Ltd (2017), Grindavik Solutions Ltd (2018), Taveta Ltd (2019), Saito Tech Ltd (2020) - and that in a February 2021 share allotment filed with the Israeli Corporations Authority, 'Zack, Shorer, and Weitzman are still the largest shareholders'. From a leaked proposal published by the Israeli outlet TheMarker it records a EUR 16 million package allowing unlimited infection attempts but monitoring of only ten devices at once.
Open sourceContemporaneous reporting on the Citizen Lab and Microsoft findings, recording that the spyware was used against human rights defenders, journalists and activists across several countries.
Open sourceThomas Brewster's first substantial public account of the company, two years before the Citizen Lab and Microsoft reports. It records that Candiru operated 'largely under the radar' with 'no website and few records available', names Eitan Achlow as chief executive, and identifies Founders Group - co-founded by Omri Lavie, one of NSO Group's three founders - as a financial backer. Brewster links the company to Uzbekistan, Saudi Arabia and the United Arab Emirates as government customers. Achlow did not respond to Forbes.
Open sourceUpdates & Milestones
- Company executives formally named as suspects
Judge Julia Tortosa Garcia-Vaso names as investigated persons two former directors of Spain's Guardia Civil, the former head of the CNI intelligence service, and executives of NSO Group and Saito Tech Ltd, over alleged disclosure of computer secrets and illegal access to computer systems. The proceedings are at the investigation stage, and no ruling had been published as of 8 August 2026.
- Barcelona court opens an investigation
A Barcelona court admits a criminal complaint brought by five Catalans coordinated by the Sentinel Alliance, and opens an investigation phase covering former Spanish police and intelligence chiefs and directors of NSO Group and Saito Tech Ltd. It is the first case explicitly asking a court to investigate the use of Candiru.
- Eight infrastructure clusters mapped
Recorded Future's Insikt Group publishes research finding eight DevilsTongue infrastructure clusters, five assessed as highly likely still active, including clusters linked to Hungary and Saudi Arabia. An Indonesia-linked cluster was active until November 2024; two Azerbaijan-associated clusters are of uncertain status.
- American fund buys the assets for up to $30m
Calcalist reports that Integrity Partners has bought Candiru's assets and moved them, with every employee, into a new entity 'not subject to U.S. government sanctions'. A first phase of $10 million is complete; the balance depends on transferring Candiru's Israeli export licences to the new company.
- Successor company incorporated
Integrity Labs Ltd is incorporated in Herzliya, directed by Naftali (Elad) Yoran, a partner at the American investment fund Integrity Partners.
- Palestinian targets again, through a Chrome flaw
Avast reports Candiru exploiting the Chrome zero-day CVE-2022-2294 against users 'in Lebanon, Turkey, Yemen, and Palestine via watering hole attacks', with journalists at a Lebanese news agency among the targets. Google fixed the flaw on 4 July 2022.
- CatalanGate
Citizen Lab documents at least 65 Catalans targeted or infected with mercenary spyware, four of them with Candiru. Joan Matamala's infection is forensically confirmed. Almost all the incidents occurred between 2017 and 2020.
- Israel cuts its cyber export list
Israel's Ministry of Defence reduces the list of countries to which Israeli firms may export offensive cyber tools from 102 to 37, removing Morocco, Mexico, Saudi Arabia and the United Arab Emirates. Every Candiru sale depends on a licence issued against that list.
- Watering-hole campaign documented
ESET publishes two waves of compromises of 21 websites, including the news site Middle East Eye, describing 'strong links' to Candiru. A Candiru executive tells Middle East Eye that the product 'is purposed to help law enforcement agencies to fight terror and crime' and that the company does not hack websites.
- Added to the US Entity List
The Commerce Department adds Candiru, with seven aliases, on evidence that it 'developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers'. The licence review policy is a presumption of denial.
- Microsoft and Citizen Lab publish together
Microsoft states it has identified over 100 victims of the DevilsTongue spyware and that 'approximately half of the victims were found in Palestinian Authority'. The victims were politicians, human rights activists, journalists, academics, embassy workers and political dissidents. Microsoft patches CVE-2021-31979 and CVE-2021-33771 the same month. Citizen Lab publishes the corporate identification and more than 750 delivery domains, many impersonating Amnesty International and the Black Lives Matter movement.
- First substantial public account
Forbes reports that Candiru operates 'largely under the radar' with 'no website and few records available', names Eitan Achlow as chief executive, identifies Founders Group - co-founded by an NSO Group founder - as a backer, and links the company to Uzbekistan, Saudi Arabia and the United Arab Emirates as government customers.
- Four changes of registered name
The company re-registers as DF Associates Ltd (2017), Grindavik Solutions Ltd (2018), Taveta Ltd (2019) and Saito Tech Ltd (2020). Citizen Lab records the sequence from Israeli corporate filings. A company that changes its registered name four times in four years is difficult to find in a procurement record, a sanctions screen or a court list.
- Company founded in Tel Aviv
Candiru Ltd is established in Tel Aviv by Yaakov Weizmann and Eran Shorer to build and sell software for breaking into computers, marketed only to governments. Isaac Zack becomes the largest shareholder within two months and takes a seat on the board.