Caramel Tsunami (SOURGUM/Candiru) is a spyware actor known for browser-based zero-day exploits via watering hole attacks.
Analyst brief
Caramel Tsunami (SOURGUM/Candiru) is a threat actor specializing in spyware attacks, recently resurfacing with an updated toolset and zero-day exploits. They primarily target specific victims through watering hole attacks, exploiting vulnerabilities in browsers like Google Chrome and using third-party signed drivers to gain Windows kernel access. Key TTPs include browser-based zero-day exploitation and kernel-level compromise via signed drivers. Defenders should focus on prompt browser patching, monitoring for suspicious driver loads, and heightened vigilance against watering hole attack vectors, especially for high-value targets.
Caramel Tsunami
SOURGUMCandiru
unknown
Caramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting specific victims through watering hole attacks. Candiru has been observed exploiting vulnerabilities in popular browsers like Google Chrome and using third-party signed drivers to gain access to the Windows kernel. They have also been linked to other spyware vendors and have been associated with extensive abuses of their surveillance tools.
What is the primary attack vector used by the Caramel Tsunami (SOURGUM/Candiru) actor during its recent resurgence?+
They primarily operate through watering hole attacks targeting specific victims.
Besides exploiting browser vulnerabilities like those in Google Chrome, what technique has Caramel Tsunami been observed using to gain Windows kernel access?+
They use third-party signed drivers to gain access to the Windows kernel.