Actors Insights|Latest update04/07/2026

Foudre

Named by BitdefenderSuspected state sponsor: Islamic Republic of Iran

Foudre is the name of an evolved malware family and associated campaign representing the Infy cluster's post-2016 operations. After Palo Alto Networks sinkholed the original Infy command and control infrastructure in 2016, the group rebuilt its surveillance platform under the Foudre name — featuring improved encryption, obfuscation, and anti-analysis capabilities. Foudre retained the core mission of the Infy cluster: long-term covert surveillance of Iranian dissidents, opposition members, and individuals connected to Iran policy. The malware was documented by Intezer and other researchers tracking continued Prince of Persia campaign activity through 2021.

First Seen:May 2016
Last Seen:Oct 2021
Indexed Reports:1
Public IOCs:19
Cluster: InfyMisp: Infy
also known as:
Operation Mermaid (Qihoo 360)Prince of Persia (Palo Alto)Foudre (Bitdefender)Infy (Palo Alto)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.