Caramel TsunamiCaramel Tsunami

Also known as: Caramel Tsunami · SOURGUM · Candiru

Known aliases
3

Profile

Caramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting specific victims through watering hole attacks. Candiru has been observed exploiting vulnerabilities in popular browsers like Google Chrome and using third-party signed drivers to gain access to the Windows kernel. They have also been linked to other spyware vendors and have been associated with extensive abuses of their surveillance tools.

Aliases· 3

Caramel TsunamiSOURGUMCandiru

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Carmine Tsunami
Actor
Mustard Tempest
Actor
Denim Tsunami
Actor
Karkadann
Actor
UNC3890
Actor
DriveSurge
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.