Actors Insights|Latest update04/07/2026

Mermaid

Named by Qihoo 360Suspected state sponsor: Islamic Republic of Iran

Operation Mermaid is a campaign designation for a subset of Infy cluster activity targeting Iranian opposition members and dissidents, documented through 2020. The operation used the Infy and Foudre malware families delivered via spear phishing to conduct long-term surveillance of targets including Kurdish communities and Iranian ethnic minorities. Operation Mermaid activity overlaps with the broader Prince of Persia campaign tracking by Intezer and shares the same Iranian state surveillance mission and technical infrastructure as the core Infy cluster.

First Seen:Apr 2010
Last Seen:Oct 2020
Indexed Reports:2
Public IOCs:233
Cluster: InfyMisp: Infy
also known as:
Operation Mermaid (Qihoo 360)Prince of Persia (Palo Alto)Foudre (Bitdefender)Infy (Palo Alto)Operation Mermaid (Qihoo 360)

Targeted Regions

Denmark
DK
Denmark
Denmark
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Apr 2010 ~ Mar 2020
Jan 2010Apr 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.