Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Keylogger,Malware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
In February 2017, an evolution of the "Infy" malware, named "Foudre" ("lightning" in French), was observed, demonstrating advanced anti-takeover techniques. Foudre, mostly written in Delphi, includes keylogging, clipboard content capture, and system information collation, aiming to evade previous countermeasures like C2 domain sinkholing. It checks internet connectivity, updates itself, and uses a Domain Generation Algorithm (DGA) for C2 domain validation. Infected via spear-phishing emails with self-executable attachments, Foudre establishes persistence by modifying the registry and using a DLL loader mechanism. It exfiltrates data via HTTP POST and employs new C2 defense mechanisms, including RSA signature verification. The report, however, does not specify targeted countries or sectors.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Azerbaijan | Verified |
| Region | Canada | Verified |
| Region | Germany | Verified |
| Region | Iran | Verified |
| Region | Iraq | Verified |
| Region | Seychelles | Verified |
| Region | Sweden | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
Extracted IOCs
- 017eab31[.]space
- 01ead12b[.]space
- 0ca0453a[.]site
- 14c7e2dc[.]space
- 15bb747b[.]site
- 15ce27c5[.]site
- 16e53040[.]space
- 17ecf559[.]site
- 1cb3c4c0[.]space
- 1d4ee030[.]space
- 23dafa1e[.]space
- 2daa46f1[.]space
- 341a436d[.]space
- 3828b6ed[.]site
- 39451f31[.]space
- 3a6e08b4[.]site
- 3c6e6571[.]space
- 3e8718c3[.]site
- 3f4572f4[.]site
- 431d73fb[.]space
- 43ec206d[.]top
- 4b6955e7[.]space
- 4e422fa7[.]space
- 4f2f867b[.]site
- 5aad7667[.]space
- 60ebc5cf[.]site
- 61e200d6[.]space
- 62c91753[.]site
- 63c0d24a[.]space
- 6bb4f456[.]space
- 76ede1bd[.]space
- 7ba775ac[.]site
- 8447b18a[.]space
- 869182ff[.]site
- 884efdfb[.]space
- 8cc7767f[.]site
- 8dceb366[.]space
- 8ee5a4e3[.]site
- 8fec61fa[.]space
- 9155ccba[.]space
- 9877fa8b[.]space
- 98e38091[.]space
- 9c1f58ab[.]site
- 9f233843[.]space
- a20af0d2[.]space
- a367590e[.]site
- a4a55efc[.]space
- a64c234e[.]site
- b4a3174b[.]space
- c4c9e3c4[.]space
- c5aeee9c[.]site
- d14b13d8[.]site
- d260045d[.]space
- d3a26e6a[.]space
- d4606998[.]site
- d50dc044[.]space
- d74b7e1d[.]space
- e00dc810[.]space
- e652fc2c[.]space
- eb18683d[.]site
- f196b269[.]site
- f8eb516c[.]space
- f9e29475[.]site
- fac983f0[.]space
- fbc046e9[.]site
- henry55.iname[.]com
- ns1.2daa46f1[.]space
- ns2.2daa46f1[.]space
- 2b37ce9e31625d8b9e51b88418d4bf38ed28c77d98ca59a09daab01be36d405a
- 4d51a0ea4ecc62456295873ff135e4d94d5899c4de749621bafcedbf4417c472
- 6bc9f6ac2f6688ed63baa29913eaf8c64738cf19933d974d25a0c26b7d01b9ac
- 7c6206eaf0c5c9c6c8d8586a626b49575942572c51458575e51cba72ba2096a4
- 7ce2c5111e3560aa6036f98b48ceafe83aa1ac3d3b33392835316c859970f8bc
- 7e73a727dc8f3c48e58468c3fd0a193a027d085f25fa274a6e187cf503f01f74
- da228831089c56743d1fbc8ef156c672017cdf46a322d847a270b9907def53a5
- db605d501d3a5ca2b0e3d8296d552fbbf048ee831be21efca407c45bf794b109
- 198[.]252.108.158
Tip: 77 related IOCs (1 IP, 68 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.
Overlaps
Source: Checkpoint - February 2021
Detection (one case): 198[.]252.108.158
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Foudre Malware Threat
Security researchers discovered a newly upgraded version of an older malware, which they are calling "Foudre." The attackers updated their tools to better protect their systems from being shut down by security professionals, allowing them to continue their data-stealing operations.
While a specific group name is not explicitly identified, the attackers are known for operating a decade-old campaign previously tracked as "Prince of Persia" or "Infy." The fact that the Iranian government previously intervened to protect the attackers' infrastructure suggests this is a state-aligned group focused on espionage.
The attack is designed for intelligence gathering rather than financial gain. The malware acts as an information stealer, quietly recording keystrokes, copying clipboard contents, and gathering data from internet browsers to send back to the attackers.
The scope of this campaign is very small and highly focused. It is not a widespread attack meant to infect as many people as possible, but rather a surgical operation directed at a carefully selected list of victims.
The report notes that the targets are primarily located within Iran, with additional victims in the United States and Iraq. In one instance, the attackers targeted the exact same specific organization or computer network in Iraq that they had attacked in previous years.
The attack begins with a deceptive email containing a malicious attachment. If the victim clicks the attachment, hidden software is installed on the computer, which then connects to a secret server to verify its instructions before quietly collecting and stealing the victim's data.
Because the attackers are highly likely aligned with state interests and focus on small, specific groups, the victims likely possess sensitive political, strategic, or intellectual information that is valuable to the attackers' sponsors.
Organizations should ensure their email security systems are scanning for and blocking dangerous attachments. Additionally, deploying modern security software that monitors computer behavior and blocks access to known bad websites will help stop the malware from successfully installing or communicating with the attackers.
This is a highly targeted issue. The malware is designed for stealthy espionage against a very small number of specific individuals or organizations, rather than being a threat to the general public.