Threats Feed
- Public
Prince of Persia APT Expands Long-Running Iranian Cyber Espionage Operations
The Prince of Persia (Infy) Iranian state-linked threat actor has conducted sustained cyber espionage operations for over a decade, targeting victims primarily in Iran, with additional infections observed across Europe, Iraq, Turkey, India, and Canada. Recent research reveals a broader operational scale than previously understood, involving multiple parallel campaigns, frequent C2 rotation, and continuous malware development. The group leveraged phishing-based initial access using malicious Excel files to deploy updated variants of Foudre and Tonnerre, including Tonnerre v50, which introduced Telegram-based command-and-control. The malware ecosystem focuses on long-term surveillance, data exfiltration, and selective victim management, demonstrating high operational maturity.
read more about Prince of Persia APT Expands Long-Running Iranian Cyber Espionage Operations - Public
Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware
Since 2007, the Infy Iranian threat group has been continuously active, launching sophisticated cyberattacks using Foudre and Tonnerre malware. Foudre collects data from infected machines and sends it to the C2 server, while Tonnerre, deployed if the victim is of interest, includes advanced spying capabilities like reverse shell and voice recording. Both use a domain generating algorithm (DGA) to evade detection by frequently changing domains. SafeBreach Labs developed a method to break Foudre’s DGA, allowing prediction and pre-emptive blocking of future C2 domains. This strategy neutralizes Foudre by preventing updates and new DGA acquisitions. The latest findings include the discovery of Tonnerre version 15 and Foudre version 24, indicating the group's evolving tactics. The report also uncovers changes in the Iranian group's infection strategy, targeting victims with both Foudre and Tonnerre, except those with certain security controls.
read more about Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware - Public
The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities
The Infy APT evolved its malware Foudre and introduced Tonnerre, targeting US and Israeli entities, including government and veteran affairs. Active since 2007, recent versions (2020) of Foudre changed tactics, using macros in documents to trigger malware, replacing earlier link-based methods. These documents, disguised as legitimate communications (e.g., featuring Iranian officials or organizations), download and execute payloads when closed. Foudre's enhancements include a sophisticated domain generation algorithm and RSA verification to evade detection and secure C2 communication. Tonnerre, a second-stage payload, offers advanced capabilities like file theft, command execution, screen capture, and audio recording. It employs DGA and RSA validation for C2, communicating over HTTP and FTP, and disguises itself as legitimate software to remain undetected.
read more about The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities - Public
Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8
The "Prince of Persia" malware campaign, attributed to Iranian origins and active for over a decade, has evolved with its new version, Foudre version 8. Initially reported by Palo Alto Networks, this malware is distributed via a WinRAR SFX archive containing malicious binaries and a politically themed video. The video serves as a distraction while the malware installs itself. Foudre is a remote access tool capable of executing commands remotely, stealing information like keystrokes and process details, and auto-updating. Its latest iteration shows significant code reuse from previous versions and introduces new functionalities. Key features include checking for the presence of certain software like Kaspersky Lab, modifying the system registry for persistence, and using a Domain Generation Algorithm. The campaign's tactics and tools are sophisticated, suggesting a focused intent on espionage or intelligence gathering.
read more about Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8 - Public
Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities
In February 2017, an evolution of the "Infy" malware, named "Foudre" ("lightning" in French), was observed, demonstrating advanced anti-takeover techniques. Foudre, mostly written in Delphi, includes keylogging, clipboard content capture, and system information collation, aiming to evade previous countermeasures like C2 domain sinkholing. It checks internet connectivity, updates itself, and uses a Domain Generation Algorithm (DGA) for C2 domain validation. Infected via spear-phishing emails with self-executable attachments, Foudre establishes persistence by modifying the registry and using a DLL loader mechanism. It exfiltrates data via HTTP POST and employs new C2 defense mechanisms, including RSA signature verification. The report, however, does not specify targeted countries or sectors.
read more about Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities - Public
Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims
The report details a decade-long cyber campaign by unidentified attackers, primarily targeting Iranian citizens among others in 35 countries. Despite the publication of an initial report, the attackers continued using the same encoding key for their operations. The defenders successfully sinkholed most of the campaign's command and control (C2) domains, limiting the attackers' communications with the majority of the victims. Analysis revealed the use of two malware variants, Infy and the more sophisticated Infy "M", with the latter being updated more regularly and targeting higher-value individuals. The attackers also attempted to evade detection by modifying their malware and adding new C2 infrastructure, including domain names and IP addresses.
read more about Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims - Public
Decade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government
The Infy malware, active since 2007 and still operational as of April 2016, was identified by Palo Alto Networks WildFire. Spear-phishing emails with malicious Word or PowerPoint attachments were sent from compromised accounts, targeting Israeli industrial organizations and a U.S. Government entity. These emails contained a multi-layer Self-Extracting Executable Archive, designed to deceive recipients into executing it. The malware, capable of evading antivirus detection, collected keylogs, browser passwords, and other sensitive data, which was then exfiltrated to C2 servers. These servers utilized a mix of Dynamic DNS providers, third-party site hosting, and first-party-registered domains. The malware's focus on specific geographic areas and sectors suggests a well-planned and targeted cyber espionage campaign against government and industrial entities in Israel, Denmark and the United States.
read more about Decade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government