Threats Feed|Mermaid|Last Updated 22/06/2026|AuthorCertfa Radar|Publish Date29/10/2020

Mermaid APT: A Continuing Threat to Government Agencies

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Keylogger,Trojan,Phishing
  • Attack Complexity: Medium
  • Threat Risk: Unknown

Threat Overview

The Mermaid (Infy, Prince of Persia) APT organization, primarily targeting government agencies, has been active since 2010 with consistent attacks and no significant operational gaps. Originating from the Middle East, they utilize the Infy backdoor, evolving into the Foudre backdoor by 2017. The group employs documents with malicious macros, embedding OLE objects to execute the Foudre backdoor via social engineering. Techniques include keylogging, registry modification, scheduled tasks for persistence, and using rundll32 for process injection. The attack also involves substantial data concealment with compressed files and web protocol communication for C2 interactions. The report indicates a sophisticated approach in both evading detection and maintaining long-term access to targeted systems.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified

Extracted IOCs

  • 00e9ce3d[.]space
  • 035ade4d[.]space
  • 07840a24[.]space
  • 08aa2c3f[.]space
  • 095f8216[.]space
  • 0a71ab21[.]space
  • 0d1c6f38[.]space
  • 1044b357[.]space
  • 1058831c[.]space
  • 12bbd9fe[.]space
  • 149a673e[.]space
  • 15d61de7[.]space
  • 19154751.space
  • 19eecf37[.]space
  • 19f2ff7c[.]space
  • 19f7493f[.]space
  • 1b857d83[.]space
  • 1bd59ba3[.]space
  • 1cb85fba[.]space
  • 1ce8b99a[.]space
  • 1e788348[.]space
  • 1e9a8d26[.]space
  • 1e9f3b65[.]space
  • 207e70f8[.]space
  • 21bc1acf[.]space
  • 2238cea1[.]space
  • 226ee19e[.]space
  • 25550ab8[.]space
  • 26d1ded6[.]space
  • 2713b4e1[.]space
  • 2ae05df2[.]space
  • 2bd8adb5[.]space
  • 2d8d99eb[.]space
  • 310860a4[.]space
  • 32370d70[.]space
  • 328cb4ca[.]space
  • 32c39cf4[.]space
  • 32dfacbf[.]space
  • 334edefd[.]space
  • 34231ae4[.]space
  • 355ac969[.]space
  • 35b268a6[.]space
  • 35e170d3[.]space
  • 3665a4bd[.]space
  • 3b69e094[.]space
  • 3b75d0df[.]space
  • 3c573cf8[.]space
  • 3d9556cf[.]space
  • 3fd3e896[.]space
  • 4162942b[.]space
  • 425df9ff[.]space
  • 42a9687b[.]space
  • 42e64045[.]space
  • 43242a72[.]space
  • 4449ee6b[.]space
  • 45303de6[.]space
  • 458b845c[.]space
  • 45c4ac62[.]space
  • 45d89c29[.]space
  • 460f5032[.]space
  • 48d4d800[.]space
  • 4a926659[.]space
  • 4b500c6e[.]space
  • 4c6ed002[.]space
  • 4c72e049[.]space
  • 50148477.space
  • 51d6ee40[.]space
  • 52523a2e[.]space
  • 553ffe37[.]space
  • 5569d108[.]space
  • 56bb2a59[.]space
  • 5779406e[.]space
  • 5a8aa97d[.]space
  • 5bb2593a[.]space
  • 5cdf9d23[.]space
  • 5de76d64[.]space
  • 62d12d71[.]space
  • 639d57a8[.]space
  • 65bce968[.]space
  • 674383c1[.]space
  • 675fb38a[.]space
  • 697fb3de[.]space
  • 69843bb8[.]space
  • 699dbdb0[.]space
  • 6bbf6f2c[.]space
  • 6bef890c[.]space
  • 6c824d15[.]space
  • 6cd2ab35[.]space
  • 6e1277c7[.]space
  • 6ee9ffa1[.]space
  • 6ef079a9[.]space
  • 6ef5cfea[.]space
  • 761b5082[.]space
  • 77eefeab[.]space
  • 7a1b5fae[.]space
  • 7d769bb7[.]space
  • 7e58b280[.]space
  • 7e6f769e[.]space
  • 801c16eb[.]space
  • 80e79e8d[.]space
  • 80fbaec6[.]space
  • 80fe1885[.]space
  • 828c2c39[.]space
  • 82dcca19[.]space
  • 85690076.space
  • 85b10e00[.]space
  • 85e1e820[.]space
  • 8771d2f2[.]space
  • 878a5a94[.]space
  • 8793dc9c[.]space
  • 87966adf[.]space
  • 8b3a6012[.]space
  • 8b6a8632[.]space
  • 8bb28844[.]space
  • 8cdf4c5d[.]space
  • 8d933684[.]space
  • 8e2590b7[.]space
  • 8ec79ed9[.]space
  • 91a37d85[.]space
  • 9378fa9b[.]space
  • 94153e82[.]space
  • 99e09f87[.]space
  • 9aceb6b0[.]space
  • 9e8d5b9e[.]space
  • a28810e1[.]space
  • a801311e[.]space
  • aa478f47[.]space
  • ab3e5cca[.]space
  • ab85e570[.]space
  • abcacd4e[.]space
  • abd6fd05[.]space
  • aca70957[.]space
  • acbb391c[.]space
  • ace82169[.]space
  • ad2a4b5e[.]space
  • af6cf507[.]space
  • b0c16d69[.]space
  • b103075e[.]space
  • b287d330[.]space
  • b2d1fc0f[.]space
  • b3e90c48[.]space
  • b484c851[.]space
  • b5bc3816[.]space
  • b8b54b75[.]space
  • b9772142[.]space
  • ba5f4063[.]space
  • bb319f1b[.]space
  • bc5c5b02[.]space
  • be1ae55b[.]space
  • bfd88f6c[.]space
  • c2bb0880[.]space
  • c383f8c7[.]space
  • c4ee3cde[.]space
  • c580e3a6[.]space
  • c5d6cc99[.]space
  • c60437c8[.]space
  • c7c65dff[.]space
  • c8dfbffa[.]space
  • c91dd5cd[.]space
  • cb5b6b94[.]space
  • cc36af8d[.]space
  • cd5870f5[.]space
  • ce7011d4[.]space
  • cfb27be3[.]space
  • d58f2077[.]space
  • d86bc591[.]space
  • da2d7bc8[.]space
  • db54a845[.]space
  • dba039c1[.]space
  • dbbc098a[.]space
  • dbef11ff[.]space
  • dc396c5c[.]space
  • dc82d5e6[.]space
  • dccdfdd8[.]space
  • dcd1cd93[.]space
  • dd40bfd1[.]space
  • df060188[.]space
  • e00be33d[.]space
  • e47fca0d[.]space
  • e6a44d13[.]space
  • e98a6b08[.]space
  • edc98626[.]space
  • eee7af11[.]space
  • f076e264[.]space
  • f08d6a02[.]space
  • f0915a49[.]space
  • f094ec0a[.]space
  • f26e30e0[.]space
  • f2b63e96[.]space
  • f2e6d8b6[.]space
  • f58b1caf[.]space
  • f5dbfa8f[.]space
  • f7e0ae1b[.]space
  • f7f92813[.]space
  • f7fc9e50[.]space
  • f922a021[.]space
  • f9c0ae4f[.]space
  • fbd87ccb[.]space
  • fc3d5084[.]space
  • fc6db6a4[.]space
  • 1a46bd6385feae53a6b8aed758e16556
  • 2c111a27d0d9d48e9470264b4c16b472
  • 4381a0c76f2bff772063e6cc6a1ac876
  • 8b8e286f64a4635e12d6d728a5669d51
  • 916e3d4c5835380c99efa802ddb4436d
  • be11401b723ec4f20be8d65c04a8003e
  • d497e0332e88341bd5ddbaa326cab977
  • dc14f029efa635d5922012904e162808
download

Tip: 208 related IOCs (0 IP, 200 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.

Overlaps

InfyThe Evolution of Infy: Cyber Espionage Campaigns Against Western Entities

Source: Checkpoint - February 2021

Detection (eight cases): 07840a24[.]space, 1e9f3b65[.]space, 35b268a6[.]space, 42a9687b[.]space, 5bb2593a[.]space, 69843bb8[.]space, 801c16eb[.]space, 8bb28844[.]space

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Mermaid (FoudreAPT) Attack Campaign

Security researchers recently uncovered a new cyberattack campaign utilizing malicious documents to deliver malware. The attackers used hidden programs within document files to secretly install updated versions of a backdoor known as "Foudre" (versions 21 and 22) onto victim computers.

The attack was carried out by a Middle Eastern threat group known as Mermaid, which is also referred to by researchers as infy, Prince of Persia, or FoudreAPT. This group is a well-established threat organization that has been conducting cyber operations since 2010.

The primary goal of this attack is cyber espionage and unauthorized data collection. Once the attackers successfully compromise a computer, they install keylogging software to record what the user types and establish a hidden connection to download additional malicious tools.

Yes, the Mermaid organization primarily targets government agencies. They use social engineering—tricking specific individuals into opening harmful files, to gain a foothold into these high-value networks.

Attackers sent victims documents containing hidden, malicious code (macros). When a victim opened the document, the code automatically extracted a hidden file, bypassed the computer's antivirus software by artificially inflating its file size, and set itself up to run automatically every time the user logged in.

Government agencies are highly attractive targets for foreign threat actors because they hold sensitive intelligence, strategic communications, and confidential data that can be used for international espionage and geopolitical advantage.

Organizations should disable untrusted macros in document files and educate staff on the dangers of opening unsolicited attachments. Additionally, IT teams should ensure their antivirus software is updated to detect file-padding tricks and monitor for unauthorized background tasks.

This is a highly targeted issue. The threat actors are specifically aiming at government agencies rather than conducting widespread, random attacks against the general public.

About Affiliation
Mermaid
Operation Mermaid is a campaign designation for a subset of Infy cluster activity targeting Iranian opposition members and dissidents, documented through 2020. The operation used the Infy and Foudre malware families delivered via spear phishing to conduct long-term surveillance of targets including Kurdish communities and Iranian ethnic minorities. Operation Mermaid activity overlaps with the broader Prince of Persia campaign tracking by Intezer and shares the same Iranian state surveillance mission and technical infrastructure as the core Infy cluster.
View Mermaid's Insights