Threats Feed|Prince of Persia|Last Updated 23/06/2026|AuthorCertfa Radar|Publish Date01/08/2017

Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Keylogger,Malware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

In February 2017, an evolution of the "Infy" malware, named "Foudre" ("lightning" in French), was observed, demonstrating advanced anti-takeover techniques. Foudre, mostly written in Delphi, includes keylogging, clipboard content capture, and system information collation, aiming to evade previous countermeasures like C2 domain sinkholing. It checks internet connectivity, updates itself, and uses a Domain Generation Algorithm (DGA) for C2 domain validation. Infected via spear-phishing emails with self-executable attachments, Foudre establishes persistence by modifying the registry and using a DLL loader mechanism. It exfiltrates data via HTTP POST and employs new C2 defense mechanisms, including RSA signature verification. The report, however, does not specify targeted countries or sectors.

Detected Targets

TypeDescriptionConfidence
RegionAzerbaijan
Verified
RegionCanada
Verified
RegionGermany
Verified
RegionIran
Verified
RegionIraq
Verified
RegionSeychelles
Verified
RegionSweden
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Extracted IOCs

  • 017eab31[.]space
  • 01ead12b[.]space
  • 0ca0453a[.]site
  • 14c7e2dc[.]space
  • 15bb747b[.]site
  • 15ce27c5[.]site
  • 16e53040[.]space
  • 17ecf559[.]site
  • 1cb3c4c0[.]space
  • 1d4ee030[.]space
  • 23dafa1e[.]space
  • 2daa46f1[.]space
  • 341a436d[.]space
  • 3828b6ed[.]site
  • 39451f31[.]space
  • 3a6e08b4[.]site
  • 3c6e6571[.]space
  • 3e8718c3[.]site
  • 3f4572f4[.]site
  • 431d73fb[.]space
  • 43ec206d[.]top
  • 4b6955e7[.]space
  • 4e422fa7[.]space
  • 4f2f867b[.]site
  • 5aad7667[.]space
  • 60ebc5cf[.]site
  • 61e200d6[.]space
  • 62c91753[.]site
  • 63c0d24a[.]space
  • 6bb4f456[.]space
  • 76ede1bd[.]space
  • 7ba775ac[.]site
  • 8447b18a[.]space
  • 869182ff[.]site
  • 884efdfb[.]space
  • 8cc7767f[.]site
  • 8dceb366[.]space
  • 8ee5a4e3[.]site
  • 8fec61fa[.]space
  • 9155ccba[.]space
  • 9877fa8b[.]space
  • 98e38091[.]space
  • 9c1f58ab[.]site
  • 9f233843[.]space
  • a20af0d2[.]space
  • a367590e[.]site
  • a4a55efc[.]space
  • a64c234e[.]site
  • b4a3174b[.]space
  • c4c9e3c4[.]space
  • c5aeee9c[.]site
  • d14b13d8[.]site
  • d260045d[.]space
  • d3a26e6a[.]space
  • d4606998[.]site
  • d50dc044[.]space
  • d74b7e1d[.]space
  • e00dc810[.]space
  • e652fc2c[.]space
  • eb18683d[.]site
  • f196b269[.]site
  • f8eb516c[.]space
  • f9e29475[.]site
  • fac983f0[.]space
  • fbc046e9[.]site
  • henry55.iname[.]com
  • ns1.2daa46f1[.]space
  • ns2.2daa46f1[.]space
  • 2b37ce9e31625d8b9e51b88418d4bf38ed28c77d98ca59a09daab01be36d405a
  • 4d51a0ea4ecc62456295873ff135e4d94d5899c4de749621bafcedbf4417c472
  • 6bc9f6ac2f6688ed63baa29913eaf8c64738cf19933d974d25a0c26b7d01b9ac
  • 7c6206eaf0c5c9c6c8d8586a626b49575942572c51458575e51cba72ba2096a4
  • 7ce2c5111e3560aa6036f98b48ceafe83aa1ac3d3b33392835316c859970f8bc
  • 7e73a727dc8f3c48e58468c3fd0a193a027d085f25fa274a6e187cf503f01f74
  • da228831089c56743d1fbc8ef156c672017cdf46a322d847a270b9907def53a5
  • db605d501d3a5ca2b0e3d8296d552fbbf048ee831be21efca407c45bf794b109
  • 198[.]252.108.158
download

Tip: 77 related IOCs (1 IP, 68 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.

Overlaps

InfyThe Evolution of Infy: Cyber Espionage Campaigns Against Western Entities

Source: Checkpoint - February 2021

Detection (one case): 198[.]252.108.158

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Foudre Malware Threat

Security researchers discovered a newly upgraded version of an older malware, which they are calling "Foudre." The attackers updated their tools to better protect their systems from being shut down by security professionals, allowing them to continue their data-stealing operations.

While a specific group name is not explicitly identified, the attackers are known for operating a decade-old campaign previously tracked as "Prince of Persia" or "Infy." The fact that the Iranian government previously intervened to protect the attackers' infrastructure suggests this is a state-aligned group focused on espionage.

The attack is designed for intelligence gathering rather than financial gain. The malware acts as an information stealer, quietly recording keystrokes, copying clipboard contents, and gathering data from internet browsers to send back to the attackers.

The scope of this campaign is very small and highly focused. It is not a widespread attack meant to infect as many people as possible, but rather a surgical operation directed at a carefully selected list of victims.

The report notes that the targets are primarily located within Iran, with additional victims in the United States and Iraq. In one instance, the attackers targeted the exact same specific organization or computer network in Iraq that they had attacked in previous years.

The attack begins with a deceptive email containing a malicious attachment. If the victim clicks the attachment, hidden software is installed on the computer, which then connects to a secret server to verify its instructions before quietly collecting and stealing the victim's data.

Because the attackers are highly likely aligned with state interests and focus on small, specific groups, the victims likely possess sensitive political, strategic, or intellectual information that is valuable to the attackers' sponsors.

Organizations should ensure their email security systems are scanning for and blocking dangerous attachments. Additionally, deploying modern security software that monitors computer behavior and blocks access to known bad websites will help stop the malware from successfully installing or communicating with the attackers.

This is a highly targeted issue. The malware is designed for stealthy espionage against a very small number of specific individuals or organizations, rather than being a threat to the general public.

About Affiliation
Prince of Persia
Prince of Persia is Intezer's campaign tracking name for continued Infy cluster operations documented from 2015 through at least 2025. The campaign represents the third documented evolution of the same Iranian surveillance infrastructure — following the original Infy malware and the Foudre rebuild — showing the group's sustained commitment to long-term espionage despite repeated public exposure. Prince of Persia campaigns target Iranian dissidents, opposition figures, and government officials using spear phishing with evolved malware families that incorporate improved anti-detection techniques, demonstrating the Infy cluster's operational longevity spanning nearly two decades.
View Prince of Persia's Insights