Decade-Old Foudre APT Adopts “Tonnerre” for Sophisticated Cyber Espionage Activities
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Downloader,Keylogger,Malicious Macro,Spyware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Bitdefender researchers uncovered ongoing activities of the Iranian Foudre APT, utilizing a new component, “Tonnerre,” targeting government and private sector entities. The Foudre malware, first identified in 2016, employs a backdoor that compromises Windows systems via a malicious document and binary, ensuring persistence and enabling data exfiltration. Enhanced tactics include improved C&C communication and resilience against forensic investigations. Tonnerre can record audio, capture screenshots, and collect files, transmitting this data to a controlled C&C. The investigation also revealed similarities with previous versions of Foudre and connections to other known malware variants like Infy M.
Extracted IOCs
- 175bd76c33491d6b97731c8755ade093
- 28e2c4d6e8194e299c62ed757ddf33e9
- 2d459929135993959cacceb0dd81a813
- 491786aa4bc9d1f09b9c793b21e80073
- 4bcdc131621953f3c0a58fe0e0c812f6
- 827626def03076264c7948d47452e725
- 956b805669e167a3327d089d7f9c37f8
- 9c1982c30c5ac019417072eb6827de07
- cfee183cf4bbe22ecbdf0d73ff16e0fb
- d01bcca6255a4f062fc59a014f407532
- d569de7d83936cb961a949b8bdcfa3f1
- dedbec01f4d61c65b24425b6039038f2
- 172[.]96.184.191
- 185[.]141.61.37
- 185[.]203.116.111
- 185[.]56.137.138
- 198[.]252.96.160
- 85[.]217.171.149
- 93[.]115.22.216
Tip: 19 related IOCs (7 IP, 0 domain, 0 URL, 0 email, 12 file hash) to this threat have been found.
Overlaps
Source: Checkpoint - February 2021
Detection (five cases): 172[.]96.184.191, 185[.]141.61.37, 185[.]203.116.111, 185[.]56.137.138, 93[.]115.22.216
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Understanding the Foudre and Tonnerre Cyber Espionage Campaign
Researchers have uncovered that an established cyber espionage campaign has been updated with a powerful new spying tool named Tonnerre. Attackers are tricking users into downloading infected files, which quietly install software capable of stealing sensitive data, recording audio, and taking regular screenshots of the victim's screen.
The attack is attributed to a sophisticated hacking group originating from Iran. This group has been active for over a decade and is known for conducting sustained, stealthy espionage campaigns against specific targets.
The primary goal of this attack is long-term espionage and data theft. The attackers aim to silently monitor victims, collect valuable documents, and secretly send this intelligence back to their own controlled servers.
Researchers have confirmed that the attacker's network remains highly active today. By intercepting one of the attackers' web addresses for a short one-week period, researchers observed over a hundred infected computers attempting to connect, though the exact total number of global victims remains hidden due to the attackers' evasive tactics.
Historically, this group targets high-value individuals within both government and private sector organizations. The spying software actively hunts for specific administrative and business files—such as office documents, databases, email archives, and security certificates—indicating a clear focus on organizational intelligence.
Attackers send a compressed folder containing a disguised document or program. Once a victim opens it, an initial hidden program is installed, which subsequently downloads a more advanced surveillance tool to systematically gather files, take pictures of the screen, and send the data back to the attackers.
Government agencies and prominent private sector organizations hold highly sensitive information, trade secrets, and strategic intelligence. Gaining covert access to this data provides the attackers or their sponsors with significant political, economic, or strategic advantages.
Organizations should train employees to avoid opening suspicious email attachments or enabling macros in documents. Additionally, security teams should update their defenses to block the known malicious web addresses associated with this campaign and monitor their computers for unauthorized scheduled tasks or hidden folders.
While the initial infected documents might be sent out somewhat broadly, the most advanced spying tools are selectively deployed only to high-value victims. This indicates a highly targeted campaign focused on specific people or organizations of interest, rather than a broad, indiscriminate attack on the general public.