Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Malicious Macro,Malware,Spyware,Trojan
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Since 2007, the Infy Iranian threat group has been continuously active, launching sophisticated cyberattacks using Foudre and Tonnerre malware. Foudre collects data from infected machines and sends it to the C2 server, while Tonnerre, deployed if the victim is of interest, includes advanced spying capabilities like reverse shell and voice recording. Both use a domain generating algorithm (DGA) to evade detection by frequently changing domains. SafeBreach Labs developed a method to break Foudre’s DGA, allowing prediction and pre-emptive blocking of future C2 domains. This strategy neutralizes Foudre by preventing updates and new DGA acquisitions. The latest findings include the discovery of Tonnerre version 15 and Foudre version 24, indicating the group's evolving tactics. The report also uncovers changes in the Iranian group's infection strategy, targeting victims with both Foudre and Tonnerre, except those with certain security controls.
Extracted IOCs
- 132d6971[.]xyz
- 1582c75f[.]xyz
- 2fe55007[.]xyz
- 4fc92184[.]site
- 6285f7c9[.]xyz
- 642a59e7[.]xyz
- 6fdaab95[.]xyz
- 8a2438cb[.]xyz
- 8b9d781a[.]xyz
- 8c8b96e5[.]xyz
- fb8ca673[.]xyz
- fd23085d[.]xyz
- pinner[.]website
- privatedns[.]com
- privatedns[.]org
- privatedns[.]website
- 015b2e6f.688[.]org
- 834972e3.privatedns[.]org
- cc08e424.privatedns[.]org
- f1host.info[.]gf
- log1host.info[.]gf
- 104[.]21.79.126
- 109[.]94.110.23
- 185[.]177.59.84
- 185[.]203.117.120
- 185[.]203.118.6
- 35[.]202.190.2
- hxxp://2fe55007[.]xyz/pinner/tdupdatex.dat
Tip: 28 related IOCs (6 IP, 21 domain, 1 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: SafeBreach - December 2025
Detection (two cases): hxxp://2fe55007[.]xyz/pinner/tdupdatex.dat, 2fe55007[.]xyz
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Understanding the Infy Threat Group's Malware Campaign
Cybersecurity researchers successfully cracked the secret formula (a Domain Generation Algorithm) that a specific malware uses to hide its command servers. By breaking this code, researchers were able to map the attackers' network, uncover new versions of their malicious software, and predict where the malware will try to connect next.
The attacks are attributed to the "Infy" Iranian threat group. They are considered one of the most persistent and active Iranian advanced persistent threat groups, with documented operations dating back to at least 2007.
The primary goal of the attack is espionage and data theft. The attackers use a two-step process: an initial infection to steal basic data and assess the computer, followed by the installation of an advanced spying tool that can open remote access and even record audio through the victim's microphone.
Recently, the attackers broadened their scope. Instead of only deploying their advanced spying tools on a select few "interesting" targets, they have begun infecting all vulnerable victims with their full suite of malware.
The report does not specify the exact industries targeted in this specific campaign. However, the group was observed monitoring and targeting specific Iranian victims, and their highly invasive spying tools suggest they are pursuing targets of intelligence value.
The attackers first infect a system with a scout malware called "Foudre," which checks the computer to ensure it doesn't have strong security software running. If the coast is clear, it downloads a second, more powerful spy tool called "Tonnerre," constantly shifting its internet communication addresses to avoid being detected and blocked by defenders.
The use of highly targeted surveillance tools, such as microphone recording and reverse shells, indicates the attackers are after sensitive, confidential, or proprietary information. The entities targeted likely hold data valuable for espionage purposes.
Organizations should ensure they have robust, up-to-date antivirus and endpoint protection software running, as the malware actively avoids installing its most dangerous components if it detects certain security tools. Network administrators can also proactively block the malware's known internet addresses to neutralize the threat.
While the group has recently become more aggressive by infecting all compromised victims with their secondary malware, the overall campaign relies on targeted, advanced persistent threat tactics rather than widespread, random internet attacks.