Foudre
Named by BitdefenderSuspected state sponsor: Islamic Republic of IranFoudre is the name of an evolved malware family and associated campaign representing the Infy cluster's post-2016 operations. After Palo Alto Networks sinkholed the original Infy command and control infrastructure in 2016, the group rebuilt its surveillance platform under the Foudre name — featuring improved encryption, obfuscation, and anti-analysis capabilities. Foudre retained the core mission of the Infy cluster: long-term covert surveillance of Iranian dissidents, opposition members, and individuals connected to Iran policy. The malware was documented by Intezer and other researchers tracking continued Prince of Persia campaign activity through 2021.
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.