Threats Feed|Infy|Last Updated 23/06/2026|AuthorCertfa Radar|Publish Date08/02/2021

The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Keylogger,Malware,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Infy APT evolved its malware Foudre and introduced Tonnerre, targeting US and Israeli entities, including government and veteran affairs. Active since 2007, recent versions (2020) of Foudre changed tactics, using macros in documents to trigger malware, replacing earlier link-based methods. These documents, disguised as legitimate communications (e.g., featuring Iranian officials or organizations), download and execute payloads when closed. Foudre's enhancements include a sophisticated domain generation algorithm and RSA verification to evade detection and secure C2 communication. Tonnerre, a second-stage payload, offers advanced capabilities like file theft, command execution, screen capture, and audio recording. It employs DGA and RSA validation for C2, communicating over HTTP and FTP, and disguises itself as legitimate software to remain undetected.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionAzerbaijan
Verified
RegionCanada
Verified
RegionDenmark
Verified
RegionGermany
Verified
RegionIndia
Verified
RegionIran
Verified
RegionIraq
Verified
RegionIsrael
Verified
RegionNetherlands
Verified
RegionRomania
Verified
RegionRussia
Verified
RegionSweden
Verified
RegionTurkey
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Extracted IOCs

  • 07840a24[.]space
  • 07840a24[.]top
  • 1e9f3b65[.]space
  • 1e9f3b65[.]top
  • 227408be[.]site
  • 35b268a6[.]space
  • 35b268a6[.]top
  • 3e4443bf[.]site
  • 42a9687b[.]space
  • 42a9687b[.]top
  • 49437329.site
  • 5bb2593a[.]space
  • 5bb2593a[.]top
  • 69843bb8[.]space
  • 69843bb8[.]top
  • 709f0af9[.]space
  • 709f0af9[.]top
  • 801c16eb[.]space
  • 801c16eb[.]top
  • 8bb28844[.]space
  • 8bb28844[.]top
  • a74d1205[.]site
  • acbde077[.]site
  • bb7d5904[.]site
  • cc7a6992[.]site
  • d9fc6eb8[.]site
  • 39507b319f55d0fec705f6dea39a0dfb
  • 78d9bed21db68b9d8c53b8f62bc5314f
  • 00cfef0d163b6cb312c07b4b49bd230121db15433204bc674350a8126665ba0f
  • 0b094d25e97cc254a53bec0943d682c1eebbf7437067b14c7b71619110dfaf83
  • 160bb722bd70b70c3e993c8eba59d8cf8117899073a4a6e42b0240d858a98dad
  • 20ffed3d57e4a49d0e20f18283ae7e5e5a7ef3249be3f04b50e78f10ec8b8989
  • 21265793d0b91845145ea37be68627855503c5505248c3ca31399cb3a9c288b4
  • 4ba5192dab8c27db8bba0e5b9d6887ea81299c88536fa590735e55b88aace759
  • 6254613570fb43ae1b95bc08868a6023c2c04f8b69fe3e5ce0ffb6db273afddc
  • 7ac73f2e5ea0ca430cf21738d3854b8a5b6a25ae4a85d140fc7e96cb87f7e2ea
  • 82d370d941fcde13dfc568fdca007bf469e5900b6f6b93c1829ab0cc7ed0f56c
  • 87c70da933731d0e0ac58ead236e0fb21f2a7e1bbeeaf37ee78d0dfbd70fd961
  • 941ca9f74fbc5e73c9c8248548c1f0d1adc646126ee6c45a0ce34fe39a52f030
  • 97dfd41db47149a815f59eae44b490ba10af588b69fbea2a84d7a2ae448a37a0
  • 9f64ec0c41623e5162e51d7631b1d29934b76984e9993083bdbdabfccba4d300
  • a64edb19e71549fb9248b27b58f911a4a1e8cd8b8e4adff93ecfb7e15a3cdad7
  • b97960c29b7c8234981728b80060a42dbe32bf625b052854a6cc2175467cca89
  • bebfbc715a0236b4fd93347f69c93aae34acbb6f9f9555284edf22378fbeb86a
  • cba270cbb084929e51bcf68145992ff3dd048887f4b9ed3a54970f1151bb1fdf
  • ccbda8a84dbeda1a66780c76fd9f507778c9fb992c7eee87e99cc3ca314009ee
  • e124c048f5ddf2d9af6dcb6f8a70d6a2b2f79a0ba9486b17b52baae98d8d23de
  • e6eed21fa1c9dc28b140a4b7633636461eefaeab214647f53d3b666158c28674
  • f48cc6f80a0783867d2f4f0e76a6b2c29d993a2d5072aa10319b48fc398d8b7a
  • f535b46ad2452d61282f615faf35993e83b6c56c9533bf22c12f97f318242e06
  • fa48da8189b9f4dd8ad011a0bac135ae82f9d493d6a9feeea5ac1abeae8ce202
  • fcd23c3e7e4027425786d4dfdf6e56912ad59bc5db935d32bf877b34bb7e4a86
  • 6931ee281c895bb9446689c8cb648e2ed353b06d454cfb4418490ef82ca07bf14853a8acc62d6586eddfb30dcbb97ffa82c5f65460708fd3a969c88e29f99160
  • 155[.]94.210.82
  • 155[.]94.211.212
  • 172[.]96.184.191
  • 185[.]141.61.37
  • 185[.]203.116.111
  • 185[.]206.144.175
  • 185[.]28.189.215
  • 185[.]56.137.138
  • 185[.]61.154.26
  • 198[.]252.108.158
  • 54[.]36.40.208
  • 54[.]37.60.199
  • 79[.]137.24.207
  • 93[.]115.22.216
download

Tip: 67 related IOCs (14 IP, 26 domain, 0 URL, 0 email, 27 file hash) to this threat have been found.

Overlaps

Prince of PersiaPrince of Persia APT Expands Long-Running Iranian Cyber Espionage Operations

Source: SafeBreach - December 2025

Detection (one case): 160bb722bd70b70c3e993c8eba59d8cf8117899073a4a6e42b0240d858a98dad

FoudreDecade-Old Foudre APT Adopts “Tonnerre” for Sophisticated Cyber Espionage Activities

Source: Bitdefender - February 2021

Detection (five cases): 172[.]96.184.191, 185[.]141.61.37, 185[.]203.116.111, 185[.]56.137.138, 93[.]115.22.216

MermaidMermaid APT: A Continuing Threat to Government Agencies

Source: Gcow Security - October 2020

Detection (eight cases): 07840a24[.]space, 1e9f3b65[.]space, 35b268a6[.]space, 42a9687b[.]space, 5bb2593a[.]space, 69843bb8[.]space, 801c16eb[.]space, 8bb28844[.]space

Prince of PersiaPrince of Persia: Evolution of Iranian Malware Campaign with Foudre V8

Source: Intezer - August 2018

Detection (one case): 185[.]61.154.26

Prince of PersiaFoudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities

Source: Palo Alto Networks - August 2017

Detection (one case): 198[.]252.108.158

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Return of the Infy Cyber Operation

Cybersecurity researchers have uncovered evidence of renewed activity from a long-running cyber operation known as "Infy" or "Prince of Persia". After a significant period of downtime following a 2016 takedown, the attackers have regrouped and dramatically improved their technical capabilities. They are now deploying a highly stealthy, previously unknown malware component designed to monitor victims and steal data.

The attacks are attributed to an Advanced Persistent Threat group backed by the government of the Islamic Republic of Iran. This operation has been active since at least 2007. The attackers have previously demonstrated unique, government-level capabilities, such as relying on the Telecommunication Company of Iran to block and redirect network traffic to regain control of their compromised victims.

The campaign is a sophisticated cyber espionage operation designed to stealthily monitor targets and extract sensitive information. Researchers believe the attackers are not financially motivated; instead, their primary goal is intelligence gathering. The newly discovered tools allow the attackers to silently steal documents, capture computer screens, and record audio from the victim's surroundings.

Historically, the operation heavily targeted victims within Iran and throughout Europe. In the most recent wave of activity, researchers identified new victims in Turkey, including a university and a state-owned investment bank. Curiously, researchers noted a glaring absence of Iranian victims in the most recent probing data, suggesting the attackers may have proactively altered their targeting or infrastructure strategies.

In the past, the campaign targeted Iranian dissidents, civil society members, the Persian press (such as BBC Persian), US Government entities, and Israeli companies. Recent attacks used decoy documents referencing an Iranian governor and a government-sponsored foundation that provides loans to veterans. This indicates a continued focus on individuals connected to regional politics, diplomacy, and state affairs.

The attackers trick victims by sending them documents that appear legitimate, such as official letters or loan forms. When the victim closes the document, a hidden script automatically runs and installs an initial foothold on the computer. This initial program securely connects to the attacker's servers to download a massive, camouflaged secondary tool that carries out the actual data theft and surveillance.

The targeted entities, which include foreign state-owned banks, universities, diplomats, and dissidents, possess highly sensitive information. Access to these individuals and organizations provides the Iranian government with valuable political intelligence, insight into opposition movements, and access to diplomatic or regional communications.

Organizations must ensure their security software does not skip scanning exceptionally large files, as these attackers intentionally use massive files to bypass basic security checks. Furthermore, users should be highly suspicious of unexpected documents and ensure that automatic macros are disabled in their document viewers, as this is the primary trick used to break into computers.

This is a highly targeted espionage campaign rather than a widespread issue affecting the general public. The threat actors carefully select their targets, utilizing decoy documents customized in Persian and targeted toward specific political or regional interests. They also use advanced cryptographic signatures to verify their own servers, ensuring their highly specialized tools remain hidden from outside researchers.

About Affiliation
Infy
Infy is a long-running Iranian cyber espionage cluster active since at least 2007, first documented publicly by Palo Alto Networks in 2016. The group primarily targets Iranian dissidents, opposition members, and foreign government officials involved in Iran policy, using Windows-based spyware to collect keystrokes, screenshots, and audio recordings. After Palo Alto disrupted its infrastructure in 2016, the group returned with a successor malware family called Foudre, demonstrating notable operational resilience. The cluster is also tracked as Prince of Persia and linked to the Operation Mermaid campaign.
View Infy's Insights