The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,Keylogger,Malware,Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Infy APT evolved its malware Foudre and introduced Tonnerre, targeting US and Israeli entities, including government and veteran affairs. Active since 2007, recent versions (2020) of Foudre changed tactics, using macros in documents to trigger malware, replacing earlier link-based methods. These documents, disguised as legitimate communications (e.g., featuring Iranian officials or organizations), download and execute payloads when closed. Foudre's enhancements include a sophisticated domain generation algorithm and RSA verification to evade detection and secure C2 communication. Tonnerre, a second-stage payload, offers advanced capabilities like file theft, command execution, screen capture, and audio recording. It employs DGA and RSA validation for C2, communicating over HTTP and FTP, and disguises itself as legitimate software to remain undetected.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Azerbaijan | Verified |
| Region | Canada | Verified |
| Region | Denmark | Verified |
| Region | Germany | Verified |
| Region | India | Verified |
| Region | Iran | Verified |
| Region | Iraq | Verified |
| Region | Israel | Verified |
| Region | Netherlands | Verified |
| Region | Romania | Verified |
| Region | Russia | Verified |
| Region | Sweden | Verified |
| Region | Turkey | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
Extracted IOCs
- 07840a24[.]space
- 07840a24[.]top
- 1e9f3b65[.]space
- 1e9f3b65[.]top
- 227408be[.]site
- 35b268a6[.]space
- 35b268a6[.]top
- 3e4443bf[.]site
- 42a9687b[.]space
- 42a9687b[.]top
- 49437329.site
- 5bb2593a[.]space
- 5bb2593a[.]top
- 69843bb8[.]space
- 69843bb8[.]top
- 709f0af9[.]space
- 709f0af9[.]top
- 801c16eb[.]space
- 801c16eb[.]top
- 8bb28844[.]space
- 8bb28844[.]top
- a74d1205[.]site
- acbde077[.]site
- bb7d5904[.]site
- cc7a6992[.]site
- d9fc6eb8[.]site
- 39507b319f55d0fec705f6dea39a0dfb
- 78d9bed21db68b9d8c53b8f62bc5314f
- 00cfef0d163b6cb312c07b4b49bd230121db15433204bc674350a8126665ba0f
- 0b094d25e97cc254a53bec0943d682c1eebbf7437067b14c7b71619110dfaf83
- 160bb722bd70b70c3e993c8eba59d8cf8117899073a4a6e42b0240d858a98dad
- 20ffed3d57e4a49d0e20f18283ae7e5e5a7ef3249be3f04b50e78f10ec8b8989
- 21265793d0b91845145ea37be68627855503c5505248c3ca31399cb3a9c288b4
- 4ba5192dab8c27db8bba0e5b9d6887ea81299c88536fa590735e55b88aace759
- 6254613570fb43ae1b95bc08868a6023c2c04f8b69fe3e5ce0ffb6db273afddc
- 7ac73f2e5ea0ca430cf21738d3854b8a5b6a25ae4a85d140fc7e96cb87f7e2ea
- 82d370d941fcde13dfc568fdca007bf469e5900b6f6b93c1829ab0cc7ed0f56c
- 87c70da933731d0e0ac58ead236e0fb21f2a7e1bbeeaf37ee78d0dfbd70fd961
- 941ca9f74fbc5e73c9c8248548c1f0d1adc646126ee6c45a0ce34fe39a52f030
- 97dfd41db47149a815f59eae44b490ba10af588b69fbea2a84d7a2ae448a37a0
- 9f64ec0c41623e5162e51d7631b1d29934b76984e9993083bdbdabfccba4d300
- a64edb19e71549fb9248b27b58f911a4a1e8cd8b8e4adff93ecfb7e15a3cdad7
- b97960c29b7c8234981728b80060a42dbe32bf625b052854a6cc2175467cca89
- bebfbc715a0236b4fd93347f69c93aae34acbb6f9f9555284edf22378fbeb86a
- cba270cbb084929e51bcf68145992ff3dd048887f4b9ed3a54970f1151bb1fdf
- ccbda8a84dbeda1a66780c76fd9f507778c9fb992c7eee87e99cc3ca314009ee
- e124c048f5ddf2d9af6dcb6f8a70d6a2b2f79a0ba9486b17b52baae98d8d23de
- e6eed21fa1c9dc28b140a4b7633636461eefaeab214647f53d3b666158c28674
- f48cc6f80a0783867d2f4f0e76a6b2c29d993a2d5072aa10319b48fc398d8b7a
- f535b46ad2452d61282f615faf35993e83b6c56c9533bf22c12f97f318242e06
- fa48da8189b9f4dd8ad011a0bac135ae82f9d493d6a9feeea5ac1abeae8ce202
- fcd23c3e7e4027425786d4dfdf6e56912ad59bc5db935d32bf877b34bb7e4a86
- 6931ee281c895bb9446689c8cb648e2ed353b06d454cfb4418490ef82ca07bf14853a8acc62d6586eddfb30dcbb97ffa82c5f65460708fd3a969c88e29f99160
- 155[.]94.210.82
- 155[.]94.211.212
- 172[.]96.184.191
- 185[.]141.61.37
- 185[.]203.116.111
- 185[.]206.144.175
- 185[.]28.189.215
- 185[.]56.137.138
- 185[.]61.154.26
- 198[.]252.108.158
- 54[.]36.40.208
- 54[.]37.60.199
- 79[.]137.24.207
- 93[.]115.22.216
Tip: 67 related IOCs (14 IP, 26 domain, 0 URL, 0 email, 27 file hash) to this threat have been found.
Overlaps
Source: SafeBreach - December 2025
Detection (one case): 160bb722bd70b70c3e993c8eba59d8cf8117899073a4a6e42b0240d858a98dad
Source: Bitdefender - February 2021
Detection (five cases): 172[.]96.184.191, 185[.]141.61.37, 185[.]203.116.111, 185[.]56.137.138, 93[.]115.22.216
Source: Gcow Security - October 2020
Detection (eight cases): 07840a24[.]space, 1e9f3b65[.]space, 35b268a6[.]space, 42a9687b[.]space, 5bb2593a[.]space, 69843bb8[.]space, 801c16eb[.]space, 8bb28844[.]space
Source: Intezer - August 2018
Detection (one case): 185[.]61.154.26
Source: Palo Alto Networks - August 2017
Detection (one case): 198[.]252.108.158
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Return of the Infy Cyber Operation
Cybersecurity researchers have uncovered evidence of renewed activity from a long-running cyber operation known as "Infy" or "Prince of Persia". After a significant period of downtime following a 2016 takedown, the attackers have regrouped and dramatically improved their technical capabilities. They are now deploying a highly stealthy, previously unknown malware component designed to monitor victims and steal data.
The attacks are attributed to an Advanced Persistent Threat group backed by the government of the Islamic Republic of Iran. This operation has been active since at least 2007. The attackers have previously demonstrated unique, government-level capabilities, such as relying on the Telecommunication Company of Iran to block and redirect network traffic to regain control of their compromised victims.
The campaign is a sophisticated cyber espionage operation designed to stealthily monitor targets and extract sensitive information. Researchers believe the attackers are not financially motivated; instead, their primary goal is intelligence gathering. The newly discovered tools allow the attackers to silently steal documents, capture computer screens, and record audio from the victim's surroundings.
Historically, the operation heavily targeted victims within Iran and throughout Europe. In the most recent wave of activity, researchers identified new victims in Turkey, including a university and a state-owned investment bank. Curiously, researchers noted a glaring absence of Iranian victims in the most recent probing data, suggesting the attackers may have proactively altered their targeting or infrastructure strategies.
In the past, the campaign targeted Iranian dissidents, civil society members, the Persian press (such as BBC Persian), US Government entities, and Israeli companies. Recent attacks used decoy documents referencing an Iranian governor and a government-sponsored foundation that provides loans to veterans. This indicates a continued focus on individuals connected to regional politics, diplomacy, and state affairs.
The attackers trick victims by sending them documents that appear legitimate, such as official letters or loan forms. When the victim closes the document, a hidden script automatically runs and installs an initial foothold on the computer. This initial program securely connects to the attacker's servers to download a massive, camouflaged secondary tool that carries out the actual data theft and surveillance.
The targeted entities, which include foreign state-owned banks, universities, diplomats, and dissidents, possess highly sensitive information. Access to these individuals and organizations provides the Iranian government with valuable political intelligence, insight into opposition movements, and access to diplomatic or regional communications.
Organizations must ensure their security software does not skip scanning exceptionally large files, as these attackers intentionally use massive files to bypass basic security checks. Furthermore, users should be highly suspicious of unexpected documents and ensure that automatic macros are disabled in their document viewers, as this is the primary trick used to break into computers.
This is a highly targeted espionage campaign rather than a widespread issue affecting the general public. The threat actors carefully select their targets, utilizing decoy documents customized in Persian and targeted toward specific political or regional interests. They also use advanced cryptographic signatures to verify their own servers, ensuring their highly specialized tools remain hidden from outside researchers.