Shoreshthe drift report · all case files
Case file

Candiru (spyware company)

Wikipedia's first sentence called it “tel aviv -based technology company offering surveillance and cyberespionage technology to governmental clients”. Today it says “private tel aviv -based company founded in 2014 which provides spyware and cyber-espionage services to governme”. Sections present on October 6, 2023 no longer exist: “Corporate profile”.
Measured, not asserted. Every count, date and revision on this page was taken from Wikipedia's own history and checked against the live article. The words quoted are theirs.
Machine-checked against the full current article on 2026-08-03.
We saved snapshots of this article over twenty years; you are reading the 2025 one. Red dashes: removed from Wikipedia since. Pale dots: rewritten; the numbered note shows what it says now. 1 tap a number or a side note to jump between them
The opening as it read in 2025

Candiru is a private Tel Aviv -based company founded in 2014 which provides spyware and cyber-espionage services to government clients. Its management and investors overlap significantly with that of NSO Group . Its operations began being uncovered in 2019 by researchers at Citizen Lab , Kaspersky , ESET (among others). Microsoft refers to the company's cyber-espionage operations as "Caramel Tsunami/SOURGUM" while Kaspersky refers to it as "SandCat" Their products exploit zero-days vulnerabilities in a variety of operating systems and web browsers to deploy persistent spyware implant (dubbed "DevilsTongue" by Microsoft) to remotely control the victim's device. Their products are also reportedly capable of compromising Mac, Android, and iPhone devices. Victims are often social engineered into visiting malicious websites which install spyware via a chain of exploits. Their business model is similar to a managed service provider for cyber-espionage, providing exploits, tools and infrastructure for government clients. It has minimal public presence, requiring employees to sign non-disclosure agreements and follow strict operational security practices to conceal their source of employment. Its corporate name has changed multiple times from 2014 to 2020. As does many Israeli technology companies it recruits heavily from Unit 8200 , which handles signals intelligence and cyberwarfare for the Israeli military . Its name and logo references the parasitic fish candiru which has the (likely apocryphal) ability to implant in the human urethra. "Israeli spyware firm linked to fake Black Lives Matter and Amnesty websites – report" . the Guardian . 2021-07-15 . "Protecting customers from a private-sector offensive actor using 0-day exploits and DevilsTongue malware" .

This is Wikipedia's own text, saved in our repository. Their copy of it is revision 1269513832.
Today
Wikipedia's first sentence called it “tel aviv -based technology company offering surveillance and cyberespionage technology to governmental clients”. Today it says “private tel aviv -based company founded in 2014 which provides spyware and cyber-espionage services to governme”. Sections present on October 6, 2023 no longer exist: “Corporate profile”. Read the current article and compare.
Oct '232025
Counts in the opening at each snapshot. Green: the word gained ground. Red: it was cut. Grey: no change.

What Wikipedia says this is

Every article opens by defining its subject. This one was redefined since 2023, and today's defining sentence is their current revision.

Then

tel aviv -based technology company offering surveillance and cyberespionage technology to governmental clients

Now

private tel aviv -based company founded in 2014 which provides spyware and cyber-espionage services to governme

Sections that no longer exist

Present on October 6, 2023, absent today, with no near-matching heading in the current article and the article shorter overall, so this is not a renamed heading or a topic absorbed into a fuller treatment. 1 section of 400 characters or more gone since October 6 2023, with the article 3,293 characters shorter.

  • Corporate profile
Struck red text is no longer in the article; dotted amber text was rewritten. Every revision id links to Wikipedia's copy; the text shown is our own saved copy. Data: /data. Wikipedia text is CC BY-SA; quoted for the record; not affiliated with Wikipedia.

← back to the drift report