DevilsTongue is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity December 3, 2025.
DevilsTongue is a Windows-targeting spyware family attributed to Candiru, a known commercial threat actor. The campaigns are described as powerful and have been observed hitting Windows users across multiple countries, underscoring Candiru's ongoing capability and the global risk to Windows endpoints.
DevilsTongue spyware, developed by Candiru, is actively targeting Windows users in multiple countries. The malware exploits vulnerabilities to infiltrate systems and gather sensitive information. Affected regions…