DevilsTongue Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 2, 2025
Last Seen
December 3, 2025

DevilsTongue is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity December 3, 2025.

Overview

DevilsTongue is a Windows-targeting spyware family attributed to Candiru, a known commercial threat actor. The campaigns are described as powerful and have been observed hitting Windows users across multiple countries, underscoring Candiru's ongoing capability and the global risk to Windows endpoints.

Related Threat Clusters

  • DevilsTongue Spyware Targets Windows Users Globally

    DevilsTongue spyware, developed by Candiru, is actively targeting Windows users in multiple countries. The malware exploits vulnerabilities to infiltrate systems and gather sensitive information. Affected regions…

    3 articles · Updated December 2, 2025

Recent Intelligence Reports

  • Global Windows Users Hit by Candiru's Powerful DevilsTongue Spyware — Cyberpress · December 3, 2025
  • Candiru’s DevilsTongue Spyware Attacking Windows Users in Multiple Countries — Cybersecuritynews · December 2, 2025

CVSS v3.1 Breakdown