Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Dropper,Keylogger,Malware,RAT,Spyware,Baiting
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The "Prince of Persia" malware campaign, attributed to Iranian origins and active for over a decade, has evolved with its new version, Foudre version 8. Initially reported by Palo Alto Networks, this malware is distributed via a WinRAR SFX archive containing malicious binaries and a politically themed video. The video serves as a distraction while the malware installs itself. Foudre is a remote access tool capable of executing commands remotely, stealing information like keystrokes and process details, and auto-updating. Its latest iteration shows significant code reuse from previous versions and introduces new functionalities. Key features include checking for the presence of certain software like Kaspersky Lab, modifying the system registry for persistence, and using a Domain Generation Algorithm. The campaign's tactics and tools are sophisticated, suggesting a focused intent on espionage or intelligence gathering.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Iran | High |
Extracted IOCs
- 177a5c4a[.]space
- 1d8bfc20[.]space
- 1f0e7a56[.]space
- 607d6cdc[.]space
- 68094ac0[.]space
- 891ec9e9[.]space
- 8fb167c7[.]space
- f8b65751[.]space
- fe19f97f[.]space
- ns1.cf75d89b[.]space
- ns2.cf75d89b[.]space
- a02ce6768662ef250d248c158f26129dd4dfab30845d07962fbfe7aa19b16db9
- c38533b85e4750e6f649cc407a50031de0984a8f3d5b90600824915433a5e218
- c7279a32329ebb1ab5c1cdbfbddb5a167e1505340c3ca72e837a222ff92665a6
- cef161a220e019acc9ae79924a477c64aac2d6cc04126bb3f4a9f8452515f40f
- d2645d16e869addd099727c3c58438c2f6935d92c00f9e4b237ef498de1dad87
- dbed2ca2e9c53dd72c3ed3ce60e603c6c91c80152f924d97d8514781e6d9e26f
- 185[.]61.154.26
Tip: 18 related IOCs (1 IP, 11 domain, 0 URL, 0 email, 6 file hash) to this threat have been found.
Overlaps
Source: Checkpoint - February 2021
Detection (one case): 185[.]61.154.26
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Prince of Persia (Foudre v8) Malware Campaign
Security researchers have uncovered a new, highly undetected version of a malicious software program known as "Foudre." This malware is hidden inside a politically themed video file that installs the malicious program in the background while the user is watching the video.
The attack is part of an ongoing campaign called "Prince of Persia," which has been active for more than 10 years. Researchers believe the threat actors behind this operation are of Iranian origin.
The primary goal is cyber espionage and data theft. The malware functions as a remote access tool, meaning once it infects a computer, the attackers can secretly execute commands, steal saved passwords from internet browsers, and record the victim's keystrokes.
While the exact number of infected individuals is actively being investigated, the campaign is highly persistent. The attackers use a specialized algorithm to continuously generate new web addresses, allowing them to maintain long-term control over infected computers.
Rather than targeting large corporations or specific industries, this campaign is heavily focused on regular individuals. Based on the decoy video used—which protests the mandatory hijab—researchers believe the targets are predominantly Iranian citizens.
Victims are tricked into opening a downloaded archive file that appears to contain only a video. Once opened, the video plays to distract the victim while the malware secretly extracts itself, hides within the computer's system files, and establishes a connection with the attackers' servers.
Citizens who are interested in or involved with political and social movements are frequently targeted by state-aligned or regional groups. Attackers seek to monitor these individuals' communications, track their activities, and gather intelligence.
Individuals should be extremely cautious when downloading or opening compressed files, especially those containing unsolicited political or social media. Organizations should ensure their antivirus tools are updated to detect the newest version of this malware and monitor their networks for suspicious automated web traffic.
This is a highly targeted issue. The specific cultural context of the decoy video strongly suggests the attackers are focused entirely on a specific demographic in the Middle East, rather than attempting a widespread global infection.