Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Downloader,Keylogger,Malware,Spyware,Trojan
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The report details a decade-long cyber campaign by unidentified attackers, primarily targeting Iranian citizens among others in 35 countries. Despite the publication of an initial report, the attackers continued using the same encoding key for their operations. The defenders successfully sinkholed most of the campaign's command and control (C2) domains, limiting the attackers' communications with the majority of the victims. Analysis revealed the use of two malware variants, Infy and the more sophisticated Infy "M", with the latter being updated more regularly and targeting higher-value individuals. The attackers also attempted to evade detection by modifying their malware and adding new C2 infrastructure, including domain names and IP addresses.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Afghanistan | Verified |
| Region | Australia | Verified |
| Region | Austria | Verified |
| Region | Bahrain | Verified |
| Region | Belgium | Verified |
| Region | Canada | Verified |
| Region | China | Verified |
| Region | Finland | Verified |
| Region | France | Verified |
| Region | Germany | Verified |
| Region | India | Verified |
| Region | Indonesia | Verified |
| Region | Iran | Verified |
| Region | Iraq | Verified |
| Region | Ireland | Verified |
| Region | Israel | Verified |
| Region | Italy | Verified |
| Region | Jordan | Verified |
| Region | Lebanon | Verified |
| Region | Malaysia | Verified |
| Region | Netherlands | Verified |
| Region | Norway | Verified |
| Region | Pakistan | Verified |
| Region | Qatar | Verified |
| Region | Romania | Verified |
| Region | Russia | Verified |
| Region | Saudi Arabia | Verified |
| Region | Sweden | Verified |
| Region | Switzerland | Verified |
| Region | Syria | Verified |
| Region | Tajikistan | Verified |
| Region | Turkey | Verified |
| Region | United Arab Emirates | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
Extracted IOCs
- bestbox3[.]com
- bestupdateserver2[.]com
- bestupdateserver[.]com
- bestwebstat[.]com
- box4035[.]net
- box4036[.]net
- box4037[.]net
- box4038[.]net
- box4039[.]net
- box4040[.]net
- box4041[.]net
- box4042[.]net
- box4043[.]net
- box4044[.]net
- box4045[.]net
- box4046[.]net
- box4047[.]net
- box4048[.]net
- box4049[.]net
- box4050[.]net
- box4051[.]net
- box4052[.]net
- box4053[.]net
- box4054[.]net
- box4055[.]net
- box4056[.]net
- box4057[.]net
- box4058[.]net
- box4059[.]net
- box4060[.]net
- box4061[.]net
- box4062[.]net
- box4063[.]net
- box4064[.]net
- box4065[.]net
- box4066[.]net
- box4067[.]net
- box4068[.]net
- box4069[.]net
- box4070[.]net
- box4071[.]net
- box4072[.]net
- box4075[.]net
- box4078[.]net
- box4079[.]net
- box4080[.]net
- box4081[.]net
- box4082[.]net
- box4083[.]net
- box4084[.]net
- box4085[.]net
- box4086[.]net
- box4087[.]net
- box4088[.]net
- box4089[.]net
- box4090[.]net
- safehostline[.]com
- updatebox4[.]com
- updateserver1[.]com
- updateserver3[.]com
- youripinfo[.]com
- bestupser.awardspace[.]info
- gstat.strangled[.]net
- lu.ige[.]es
- p208.ige[.]es
- secup.soon[.]it
- us1s2.strangled[.]net
- uvps1.cotbm[.]com
- 583349b7a2385a1e8de682a43351798ca113cbbb80686193ecf9a61e6942786a
- f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27
- 138[.]201.0.134
- 138[.]201.47.150
- 138[.]201.47.153
- 138[.]201.47.158
- 144[.]76.250.205
- 5[.]9.94.34
Tip: 76 related IOCs (6 IP, 68 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.
Overlaps
Source: QAX - March 2020
Detection (three cases): bestupdateserver[.]com, bestwebstat[.]com, updateserver1[.]com
Source: Palo Alto Networks - May 2016
Detection (14 cases): bestbox3[.]com, bestupdateserver[.]com, bestupdateserver2[.]com, bestupser.awardspace[.]info, bestwebstat[.]com, box4054[.]net, gstat.strangled[.]net, lu.ige[.]es, secup.soon[.]it, updatebox4[.]com, updateserver1[.]com, updateserver3[.]com, us1s2.strangled[.]net, youripinfo[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The "Infy" Malware Campaign
Cybersecurity researchers successfully disrupted a ten-year-long cyberespionage campaign. By taking control of the servers the attackers used to communicate with infected computers, researchers permanently disabled the attackers' ability to access their victims or steal further data.
The report does not explicitly name a specific group or country behind the operation. However, the operators demonstrated high levels of dedication, running a coordinated espionage campaign for a full decade and actively updating their malicious tools to maintain secret access.
The primary goal of this campaign was intelligence gathering and data theft. The malicious software was designed to secretly monitor computers, log keystrokes, and steal a massive variety of private files, documents, databases, and media.
The campaign had a relatively low number of victims, pointing to a highly focused and deliberate effort rather than a mass-infection approach. Researchers identified 326 compromised computer systems spread across 35 different countries.
The campaign primarily targeted government and industry interests worldwide, with a very heavy emphasis on Iranian citizens, who made up nearly a third of all victims. The attackers also deployed much more sophisticated software against specific individuals they deemed to be high-value targets.
Attackers infected computers with a hidden program called "Infy," which quietly mapped out the system, recorded user activity, and hunted for valuable files. This stolen data was then locked up with a custom code and secretly transmitted back to servers controlled by the espionage group.
Government and industry personnel frequently have access to sensitive intellectual property, state secrets, or confidential internal communications. Additionally, the targeted citizens likely possessed valuable personal information or communications of direct interest to the espionage operators.
Organizations must ensure their anti-virus and security software are active and up to date, as the newest versions of this malware actively searched for ways to bypass common security tools. Maintaining strong network monitoring can also help catch unauthorized attempts to send stolen data out of the network.
This was a highly targeted issue. The attackers deliberately focused their efforts on a small, specific group of victims and paid very close attention to their highest-value targets to ensure their spying tools remained undetected.