Threats Feed
- Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Prince of Persia APT Expands Long-Running Iranian Cyber Espionage Operations
The Prince of Persia (Infy) Iranian state-linked threat actor has conducted sustained cyber espionage operations for over a decade, targeting victims primarily in Iran, with additional infections observed across Europe, Iraq, Turkey, India, and Canada. Recent research reveals a broader operational scale than previously understood, involving multiple parallel campaigns, frequent C2 rotation, and continuous malware development. The group leveraged phishing-based initial access using malicious Excel files to deploy updated variants of Foudre and Tonnerre, including Tonnerre v50, which introduced Telegram-based command-and-control. The malware ecosystem focuses on long-term surveillance, data exfiltration, and selective victim management, demonstrating high operational maturity.
read more about Prince of Persia APT Expands Long-Running Iranian Cyber Espionage Operations - Public
Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers
SafeBreach Labs discovered an Iranian threat actor exploiting the MSHTML vulnerability (CVE-2021-40444) to infect Farsi-speaking victims with the PowerShortShell stealer via spear phishing. The attack, first reported in September 2021, involved a malicious Word document connecting to a server, downloading a DLL, and executing a PowerShell script. This script collected data, including screenshots and files, and exfiltrated it to the attacker's server. The campaign targeted Iranians abroad, particularly in the United States, suggesting ties to Iran's Islamic regime.
read more about Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers - Public
Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware
Since 2007, the Infy Iranian threat group has been continuously active, launching sophisticated cyberattacks using Foudre and Tonnerre malware. Foudre collects data from infected machines and sends it to the C2 server, while Tonnerre, deployed if the victim is of interest, includes advanced spying capabilities like reverse shell and voice recording. Both use a domain generating algorithm (DGA) to evade detection by frequently changing domains. SafeBreach Labs developed a method to break Foudre’s DGA, allowing prediction and pre-emptive blocking of future C2 domains. This strategy neutralizes Foudre by preventing updates and new DGA acquisitions. The latest findings include the discovery of Tonnerre version 15 and Foudre version 24, indicating the group's evolving tactics. The report also uncovers changes in the Iranian group's infection strategy, targeting victims with both Foudre and Tonnerre, except those with certain security controls.
read more about Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware - Public
Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware
Since 2007, the Infy Iranian threat group has been continuously active, launching sophisticated cyberattacks using Foudre and Tonnerre malware. Foudre collects data from infected machines and sends it to the C2 server, while Tonnerre, deployed if the victim is of interest, includes advanced spying capabilities like reverse shell and voice recording. Both use a domain generating algorithm (DGA) to evade detection by frequently changing domains. SafeBreach Labs developed a method to break Foudre’s DGA, allowing prediction and pre-emptive blocking of future C2 domains. This strategy neutralizes Foudre by preventing updates and new DGA acquisitions. The latest findings include the discovery of Tonnerre version 15 and Foudre version 24, indicating the group's evolving tactics. The report also uncovers changes in the Iranian group's infection strategy, targeting victims with both Foudre and Tonnerre, except those with certain security controls.
read more about Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware - Public
Decade-Old Foudre APT Adopts “Tonnerre” for Sophisticated Cyber Espionage Activities
Bitdefender researchers uncovered ongoing activities of the Iranian Foudre APT, utilizing a new component, “Tonnerre,” targeting government and private sector entities. The Foudre malware, first identified in 2016, employs a backdoor that compromises Windows systems via a malicious document and binary, ensuring persistence and enabling data exfiltration. Enhanced tactics include improved C&C communication and resilience against forensic investigations. Tonnerre can record audio, capture screenshots, and collect files, transmitting this data to a controlled C&C. The investigation also revealed similarities with previous versions of Foudre and connections to other known malware variants like Infy M.
read more about Decade-Old Foudre APT Adopts “Tonnerre” for Sophisticated Cyber Espionage Activities - Public
The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities
The Infy APT evolved its malware Foudre and introduced Tonnerre, targeting US and Israeli entities, including government and veteran affairs. Active since 2007, recent versions (2020) of Foudre changed tactics, using macros in documents to trigger malware, replacing earlier link-based methods. These documents, disguised as legitimate communications (e.g., featuring Iranian officials or organizations), download and execute payloads when closed. Foudre's enhancements include a sophisticated domain generation algorithm and RSA verification to evade detection and secure C2 communication. Tonnerre, a second-stage payload, offers advanced capabilities like file theft, command execution, screen capture, and audio recording. It employs DGA and RSA validation for C2, communicating over HTTP and FTP, and disguises itself as legitimate software to remain undetected.
read more about The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities - Public
Mermaid APT: A Continuing Threat to Government Agencies
The Mermaid (Infy, Prince of Persia) APT organization, primarily targeting government agencies, has been active since 2010 with consistent attacks and no significant operational gaps. Originating from the Middle East, they utilize the Infy backdoor, evolving into the Foudre backdoor by 2017. The group employs documents with malicious macros, embedding OLE objects to execute the Foudre backdoor via social engineering. Techniques include keylogging, registry modification, scheduled tasks for persistence, and using rundll32 for process injection. The attack also involves substantial data concealment with compressed files and web protocol communication for C2 interactions. The report indicates a sophisticated approach in both evading detection and maintaining long-term access to targeted systems.
read more about Mermaid APT: A Continuing Threat to Government Agencies - Public
Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8
The "Prince of Persia" malware campaign, attributed to Iranian origins and active for over a decade, has evolved with its new version, Foudre version 8. Initially reported by Palo Alto Networks, this malware is distributed via a WinRAR SFX archive containing malicious binaries and a politically themed video. The video serves as a distraction while the malware installs itself. Foudre is a remote access tool capable of executing commands remotely, stealing information like keystrokes and process details, and auto-updating. Its latest iteration shows significant code reuse from previous versions and introduces new functionalities. Key features include checking for the presence of certain software like Kaspersky Lab, modifying the system registry for persistence, and using a Domain Generation Algorithm. The campaign's tactics and tools are sophisticated, suggesting a focused intent on espionage or intelligence gathering.
read more about Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8 - Public
Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities
In February 2017, an evolution of the "Infy" malware, named "Foudre" ("lightning" in French), was observed, demonstrating advanced anti-takeover techniques. Foudre, mostly written in Delphi, includes keylogging, clipboard content capture, and system information collation, aiming to evade previous countermeasures like C2 domain sinkholing. It checks internet connectivity, updates itself, and uses a Domain Generation Algorithm (DGA) for C2 domain validation. Infected via spear-phishing emails with self-executable attachments, Foudre establishes persistence by modifying the registry and using a DLL loader mechanism. It exfiltrates data via HTTP POST and employs new C2 defense mechanisms, including RSA signature verification. The report, however, does not specify targeted countries or sectors.
read more about Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities - Public
Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims
The report details a decade-long cyber campaign by unidentified attackers, primarily targeting Iranian citizens among others in 35 countries. Despite the publication of an initial report, the attackers continued using the same encoding key for their operations. The defenders successfully sinkholed most of the campaign's command and control (C2) domains, limiting the attackers' communications with the majority of the victims. Analysis revealed the use of two malware variants, Infy and the more sophisticated Infy "M", with the latter being updated more regularly and targeting higher-value individuals. The attackers also attempted to evade detection by modifying their malware and adding new C2 infrastructure, including domain names and IP addresses.
read more about Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims - Public
Decade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government
The Infy malware, active since 2007 and still operational as of April 2016, was identified by Palo Alto Networks WildFire. Spear-phishing emails with malicious Word or PowerPoint attachments were sent from compromised accounts, targeting Israeli industrial organizations and a U.S. Government entity. These emails contained a multi-layer Self-Extracting Executable Archive, designed to deceive recipients into executing it. The malware, capable of evading antivirus detection, collected keylogs, browser passwords, and other sensitive data, which was then exfiltrated to C2 servers. These servers utilized a mix of Dynamic DNS providers, third-party site hosting, and first-party-registered domains. The malware's focus on specific geographic areas and sectors suggests a well-planned and targeted cyber espionage campaign against government and industrial entities in Israel, Denmark and the United States.
read more about Decade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government