Threats Feed|Prince of Persia|Last Updated 26/06/2026|AuthorCertfa Radar|Publish Date28/06/2016

Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Downloader,Keylogger,Malware,Spyware,Trojan
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The report details a decade-long cyber campaign by unidentified attackers, primarily targeting Iranian citizens among others in 35 countries. Despite the publication of an initial report, the attackers continued using the same encoding key for their operations. The defenders successfully sinkholed most of the campaign's command and control (C2) domains, limiting the attackers' communications with the majority of the victims. Analysis revealed the use of two malware variants, Infy and the more sophisticated Infy "M", with the latter being updated more regularly and targeting higher-value individuals. The attackers also attempted to evade detection by modifying their malware and adding new C2 infrastructure, including domain names and IP addresses.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionAfghanistan
Verified
RegionAustralia
Verified
RegionAustria
Verified
RegionBahrain
Verified
RegionBelgium
Verified
RegionCanada
Verified
RegionChina
Verified
RegionFinland
Verified
RegionFrance
Verified
RegionGermany
Verified
RegionIndia
Verified
RegionIndonesia
Verified
RegionIran
Verified
RegionIraq
Verified
RegionIreland
Verified
RegionIsrael
Verified
RegionItaly
Verified
RegionJordan
Verified
RegionLebanon
Verified
RegionMalaysia
Verified
RegionNetherlands
Verified
RegionNorway
Verified
RegionPakistan
Verified
RegionQatar
Verified
RegionRomania
Verified
RegionRussia
Verified
RegionSaudi Arabia
Verified
RegionSweden
Verified
RegionSwitzerland
Verified
RegionSyria
Verified
RegionTajikistan
Verified
RegionTurkey
Verified
RegionUnited Arab Emirates
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Extracted IOCs

  • bestbox3[.]com
  • bestupdateserver2[.]com
  • bestupdateserver[.]com
  • bestwebstat[.]com
  • box4035[.]net
  • box4036[.]net
  • box4037[.]net
  • box4038[.]net
  • box4039[.]net
  • box4040[.]net
  • box4041[.]net
  • box4042[.]net
  • box4043[.]net
  • box4044[.]net
  • box4045[.]net
  • box4046[.]net
  • box4047[.]net
  • box4048[.]net
  • box4049[.]net
  • box4050[.]net
  • box4051[.]net
  • box4052[.]net
  • box4053[.]net
  • box4054[.]net
  • box4055[.]net
  • box4056[.]net
  • box4057[.]net
  • box4058[.]net
  • box4059[.]net
  • box4060[.]net
  • box4061[.]net
  • box4062[.]net
  • box4063[.]net
  • box4064[.]net
  • box4065[.]net
  • box4066[.]net
  • box4067[.]net
  • box4068[.]net
  • box4069[.]net
  • box4070[.]net
  • box4071[.]net
  • box4072[.]net
  • box4075[.]net
  • box4078[.]net
  • box4079[.]net
  • box4080[.]net
  • box4081[.]net
  • box4082[.]net
  • box4083[.]net
  • box4084[.]net
  • box4085[.]net
  • box4086[.]net
  • box4087[.]net
  • box4088[.]net
  • box4089[.]net
  • box4090[.]net
  • safehostline[.]com
  • updatebox4[.]com
  • updateserver1[.]com
  • updateserver3[.]com
  • youripinfo[.]com
  • bestupser.awardspace[.]info
  • gstat.strangled[.]net
  • lu.ige[.]es
  • p208.ige[.]es
  • secup.soon[.]it
  • us1s2.strangled[.]net
  • uvps1.cotbm[.]com
  • 583349b7a2385a1e8de682a43351798ca113cbbb80686193ecf9a61e6942786a
  • f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27
  • 138[.]201.0.134
  • 138[.]201.47.150
  • 138[.]201.47.153
  • 138[.]201.47.158
  • 144[.]76.250.205
  • 5[.]9.94.34
download

Tip: 76 related IOCs (6 IP, 68 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

MermaidOperation Mermaid: A Decade of Targeted APT Attacks on Government Entities

Source: QAX - March 2020

Detection (three cases): bestupdateserver[.]com, bestwebstat[.]com, updateserver1[.]com

Prince of PersiaDecade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government

Source: Palo Alto Networks - May 2016

Detection (14 cases): bestbox3[.]com, bestupdateserver[.]com, bestupdateserver2[.]com, bestupser.awardspace[.]info, bestwebstat[.]com, box4054[.]net, gstat.strangled[.]net, lu.ige[.]es, secup.soon[.]it, updatebox4[.]com, updateserver1[.]com, updateserver3[.]com, us1s2.strangled[.]net, youripinfo[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The "Infy" Malware Campaign

Cybersecurity researchers successfully disrupted a ten-year-long cyberespionage campaign. By taking control of the servers the attackers used to communicate with infected computers, researchers permanently disabled the attackers' ability to access their victims or steal further data.

The report does not explicitly name a specific group or country behind the operation. However, the operators demonstrated high levels of dedication, running a coordinated espionage campaign for a full decade and actively updating their malicious tools to maintain secret access.

The primary goal of this campaign was intelligence gathering and data theft. The malicious software was designed to secretly monitor computers, log keystrokes, and steal a massive variety of private files, documents, databases, and media.

The campaign had a relatively low number of victims, pointing to a highly focused and deliberate effort rather than a mass-infection approach. Researchers identified 326 compromised computer systems spread across 35 different countries.

The campaign primarily targeted government and industry interests worldwide, with a very heavy emphasis on Iranian citizens, who made up nearly a third of all victims. The attackers also deployed much more sophisticated software against specific individuals they deemed to be high-value targets.

Attackers infected computers with a hidden program called "Infy," which quietly mapped out the system, recorded user activity, and hunted for valuable files. This stolen data was then locked up with a custom code and secretly transmitted back to servers controlled by the espionage group.

Government and industry personnel frequently have access to sensitive intellectual property, state secrets, or confidential internal communications. Additionally, the targeted citizens likely possessed valuable personal information or communications of direct interest to the espionage operators.

Organizations must ensure their anti-virus and security software are active and up to date, as the newest versions of this malware actively searched for ways to bypass common security tools. Maintaining strong network monitoring can also help catch unauthorized attempts to send stolen data out of the network.

This was a highly targeted issue. The attackers deliberately focused their efforts on a small, specific group of victims and paid very close attention to their highest-value targets to ensure their spying tools remained undetected.

About Affiliation
Prince of Persia
Prince of Persia is Intezer's campaign tracking name for continued Infy cluster operations documented from 2015 through at least 2025. The campaign represents the third documented evolution of the same Iranian surveillance infrastructure — following the original Infy malware and the Foudre rebuild — showing the group's sustained commitment to long-term espionage despite repeated public exposure. Prince of Persia campaigns target Iranian dissidents, opposition figures, and government officials using spear phishing with evolved malware families that incorporate improved anti-detection techniques, demonstrating the Infy cluster's operational longevity spanning nearly two decades.
View Prince of Persia's Insights