Revealed: Top Secret Israeli Hackers For Hire

Candiru, named after an Amazon fish known to parasitise the human urethra, recruits heavily from 8200 intelligence unit and sells offensive tools for hacking computer systems. The name fits the company’s business, which is offensive cyber, the technology used to hack into computers or smartphones and spy on users.

In the Tel Aviv building that acts as its headquarters, Candiru name is not in the directory. Also it is not on a website as it doesn’t have one. Its 120 or so employees don’t post profiles on LinkedIn and sign strict confidentiality agreements. Inquiries by TheMarker elicited a polite but firm “no comment”.

Offensive cyber is a big business in Israel, with industry sources saying it generates about $1 billion in sales a year. The biggest and most controversial of the players is NSO, which has been cited repeatedly for selling its equipment to Arabia and Mexico that have used them to spy and crack-down on dissidents.

NSO’s specialty is hacking smartphones. Candiru’s hacking tools are used to break into computers and servers, although some sources told TheMarker that it also has technology for breaking into mobile devices as well. 

Unlike NSO, Candiru is more conservative in its choice of customers. Most of them are in Western Europe and none of them are from Africa. In fact, the company reportedly doesn’t sell equipment to Israel, although that is for business, not political, reasons, they say.

“For example, if Germany needs offensive cyber equipment for some national security matter, it will develop it in-house without question,” explained one source, who asked not to be identified. “But if it needs to contend with human trafficking from Turkey, for instance, it will buy cyber gear from an outside source where the issue is less sensitive.”

Candiru’s sales policy is an internal decision, and many Israeli companies in the business have found themselves in hot water for selling to regimes with poor records on democracy and human rights.

Israel regards offensive cyber tools as no different than other weapons and exports must be approved by the Defense Ministry. However, while the ministry is sensitive to security risks to Israel from exports, it is less concerns about democracy and human rights violations by buyers.

Candiru is also different from many other offensive cyber companies, such as hacking team and FinFisher, that only sell attack tools, because Candiru sells a complete system.

“They have a user interface through which the customer sees how many targets have been penetrated, what information has been obtained and so forth,” said one source. 

“In addition, they offer a very sophisticated service, so that if a certain attack tool doesn’t work they’ll produce a new one that will work. They sell a pre-loaded 'cartridge' of attack tools.”

Formed four years ago, Candiru is shrouded in secrecy. It is believed to employ 120 people and generate annual sales of $30 million a year, but that is only speculation by outsiders. If true, that would make it Israel’s second-largest offensive cyber company after NSO, not counting publicly traded Verint and general defense companies.

What is known is that Candiru’s founder is Isaac Zack, who was also a founder of NSO. Zack is a venture capital investor and among the founders of the investment firms Founders Group and Pico Venture Partners.

Candiru’s CEO is Eitan Achlow, who was previously an executive at the Israeli ride-sharing company Gett. But in line with Candiru’s veil of secrecy, Achlow’s LinkedIn page lists him as working in a company in stealth mode, a startup industry term for companies that haven’t launched a product and are working without publicity.

According to the Dun & Bradstreet guide, Zack is on the boards of 13 companies, among them the cybersecurity startups Cy-Ot and Orchestra, all of them in the field of protective cybersecurity. Keeping with the secrecy surrounding Candiru, its name isn’t listed among Zack’s directorships.

That is because Candiru is not the company’s registered name. It was originally registered under the name Grindavik Solutions in September 2014. It changed it to LDF Associates in March 2017 and back to Grindavik last April. 

Like other companies in Israel's renowned cybersecurity industry, Candiru recruits heavily from the Israel Defense Forces 8200 intelligence unit. They are typically paid 80,000 shekels ($21,400) a month and some make 90,000.

“They take the best hackers…,” said one cybersecurity entrepreneur, who spoke on condition of anonymity. “Candiru has no defined work conditions, you can do what you want. They even have one employee that lives in France and starts up his computer when he feels like it.”

Haaretz:      Guardian:     Computing

You Might Also Read:

Israel: The Cyber Power:

 

« Optimising Maritime Cybersecurity
Hackers Demand Ransom For Stolen 911 Documents »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

4Secure

4Secure

4Secure is a cyber security company providing services and solutions to counter and respond to the most sophisticated and targeted cyber threats.

UCD Centre for Cybersecurity and Cybercrime Investigation

UCD Centre for Cybersecurity and Cybercrime Investigation

UCD Centre for Cybersecurity and Cybercrime Investigation is Europe's leading centre for research & education in cybersecurity, cybercrime and digital forensics.

Virtustream

Virtustream

The Virtustream Enterprise Class Cloud provides a secure, highly available, Infrastructure as a Service (IaaS) to enterprises and government customers.

WireX Systems

WireX Systems

WireX is an innovative network intelligence and forensics company that is changing the way businesses resolve cyber-attacks.

Bittium

Bittium

Bittium provides proven information security solutions for mobile devices and portable computers.

Schneider Electric

Schneider Electric

Schneider Electric develops connected technologies and solutions to manage energy and process in ways that are safe, reliable and sustainable.

Huntsman Security

Huntsman Security

Huntsman Security provides technology to enable real-time security monitoring and immediate visibility of advanced threats and compliance issues.

OneWelcome

OneWelcome

Onegini and iWelcome have merged to become OneWelcome, the largest European Identity Access Management Saas Vendor.

FoxGuard Solutions

FoxGuard Solutions

FoxGuard Solutions develops customized cyber security, compliance and industrial computing solutions for critical infrastructure entities and control system vendors.

Information Technology Industry Development Agency (ITIDA)

Information Technology Industry Development Agency (ITIDA)

ITIDA has two broad goals: building the capacities of Egypt’s local information and communications technology (ICT) industry and attracting foreign direct investments to boost the ICT sector.

ATIA

ATIA

ATIA provides consulting services in the design and implementation of IT system, Information Security, ISO certification, and professional IT training and education.

Cybersecurity Tech Accord

Cybersecurity Tech Accord

The Cybersecurity Tech Accord promotes a safer online world by fostering collaboration among global technology companies.

SaltStack

SaltStack

SaltStack develops award-winning intelligent IT automation software. We help businesses more efficiently secure and manage all aspects of their digital infrastructure.

CryptoCurrency Certification Consortium (C4)

CryptoCurrency Certification Consortium (C4)

The CryptoCurrency Certification Consortium is a non-profit organization that provides certifications to professionals who perform cryptocurrency-related services.

SOOS

SOOS

SOOS is the easy-to-integrate software security solution for your whole team. Build, catch, and fix vulnerabilities with SOOS Software Composition Analysis.

Digital Catapult

Digital Catapult

Digital Catapult is the UK authority on advanced digital technology. We bring out the best in business by accelerating new possibilities with advanced digital technologies.