Threats Feed|Infy|Last Updated 25/06/2026|AuthorCertfa Radar|Publish Date11/10/2021

Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Malicious Macro,Malware,Spyware,Trojan
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Since 2007, the Infy Iranian threat group has been continuously active, launching sophisticated cyberattacks using Foudre and Tonnerre malware. Foudre collects data from infected machines and sends it to the C2 server, while Tonnerre, deployed if the victim is of interest, includes advanced spying capabilities like reverse shell and voice recording. Both use a domain generating algorithm (DGA) to evade detection by frequently changing domains. SafeBreach Labs developed a method to break Foudre’s DGA, allowing prediction and pre-emptive blocking of future C2 domains. This strategy neutralizes Foudre by preventing updates and new DGA acquisitions. The latest findings include the discovery of Tonnerre version 15 and Foudre version 24, indicating the group's evolving tactics. The report also uncovers changes in the Iranian group's infection strategy, targeting victims with both Foudre and Tonnerre, except those with certain security controls.

Extracted IOCs

  • 132d6971[.]xyz
  • 1582c75f[.]xyz
  • 2fe55007[.]xyz
  • 4fc92184[.]site
  • 6285f7c9[.]xyz
  • 642a59e7[.]xyz
  • 6fdaab95[.]xyz
  • 8a2438cb[.]xyz
  • 8b9d781a[.]xyz
  • 8c8b96e5[.]xyz
  • fb8ca673[.]xyz
  • fd23085d[.]xyz
  • pinner[.]website
  • privatedns[.]com
  • privatedns[.]org
  • privatedns[.]website
  • 015b2e6f.688[.]org
  • 834972e3.privatedns[.]org
  • cc08e424.privatedns[.]org
  • f1host.info[.]gf
  • log1host.info[.]gf
  • 104[.]21.79.126
  • 109[.]94.110.23
  • 185[.]177.59.84
  • 185[.]203.117.120
  • 185[.]203.118.6
  • 35[.]202.190.2
  • hxxp://2fe55007[.]xyz/pinner/tdupdatex.dat
download

Tip: 28 related IOCs (6 IP, 21 domain, 1 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

Prince of PersiaPrince of Persia APT Expands Long-Running Iranian Cyber Espionage Operations

Source: SafeBreach - December 2025

Detection (two cases): hxxp://2fe55007[.]xyz/pinner/tdupdatex.dat, 2fe55007[.]xyz

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Understanding the Infy Threat Group's Malware Campaign

Cybersecurity researchers successfully cracked the secret formula (a Domain Generation Algorithm) that a specific malware uses to hide its command servers. By breaking this code, researchers were able to map the attackers' network, uncover new versions of their malicious software, and predict where the malware will try to connect next.

The attacks are attributed to the "Infy" Iranian threat group. They are considered one of the most persistent and active Iranian advanced persistent threat groups, with documented operations dating back to at least 2007.

The primary goal of the attack is espionage and data theft. The attackers use a two-step process: an initial infection to steal basic data and assess the computer, followed by the installation of an advanced spying tool that can open remote access and even record audio through the victim's microphone.

Recently, the attackers broadened their scope. Instead of only deploying their advanced spying tools on a select few "interesting" targets, they have begun infecting all vulnerable victims with their full suite of malware.

The report does not specify the exact industries targeted in this specific campaign. However, the group was observed monitoring and targeting specific Iranian victims, and their highly invasive spying tools suggest they are pursuing targets of intelligence value.

The attackers first infect a system with a scout malware called "Foudre," which checks the computer to ensure it doesn't have strong security software running. If the coast is clear, it downloads a second, more powerful spy tool called "Tonnerre," constantly shifting its internet communication addresses to avoid being detected and blocked by defenders.

The use of highly targeted surveillance tools, such as microphone recording and reverse shells, indicates the attackers are after sensitive, confidential, or proprietary information. The entities targeted likely hold data valuable for espionage purposes.

Organizations should ensure they have robust, up-to-date antivirus and endpoint protection software running, as the malware actively avoids installing its most dangerous components if it detects certain security tools. Network administrators can also proactively block the malware's known internet addresses to neutralize the threat.

While the group has recently become more aggressive by infecting all compromised victims with their secondary malware, the overall campaign relies on targeted, advanced persistent threat tactics rather than widespread, random internet attacks.

About Affiliation
Infy
Infy is a long-running Iranian cyber espionage cluster active since at least 2007, first documented publicly by Palo Alto Networks in 2016. The group primarily targets Iranian dissidents, opposition members, and foreign government officials involved in Iran policy, using Windows-based spyware to collect keystrokes, screenshots, and audio recordings. After Palo Alto disrupted its infrastructure in 2016, the group returned with a successor malware family called Foudre, demonstrating notable operational resilience. The cluster is also tracked as Prince of Persia and linked to the Operation Mermaid campaign.
View Infy's Insights