Threats Feed|Prince of Persia|Last Updated 02/07/2026|AuthorCertfa Radar|Publish Date17/08/2018

Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Dropper,Keylogger,Malware,RAT,Spyware,Baiting
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The "Prince of Persia" malware campaign, attributed to Iranian origins and active for over a decade, has evolved with its new version, Foudre version 8. Initially reported by Palo Alto Networks, this malware is distributed via a WinRAR SFX archive containing malicious binaries and a politically themed video. The video serves as a distraction while the malware installs itself. Foudre is a remote access tool capable of executing commands remotely, stealing information like keystrokes and process details, and auto-updating. Its latest iteration shows significant code reuse from previous versions and introduces new functionalities. Key features include checking for the presence of certain software like Kaspersky Lab, modifying the system registry for persistence, and using a Domain Generation Algorithm. The campaign's tactics and tools are sophisticated, suggesting a focused intent on espionage or intelligence gathering.

Detected Targets

TypeDescriptionConfidence
RegionIran
High

Extracted IOCs

  • 177a5c4a[.]space
  • 1d8bfc20[.]space
  • 1f0e7a56[.]space
  • 607d6cdc[.]space
  • 68094ac0[.]space
  • 891ec9e9[.]space
  • 8fb167c7[.]space
  • f8b65751[.]space
  • fe19f97f[.]space
  • ns1.cf75d89b[.]space
  • ns2.cf75d89b[.]space
  • a02ce6768662ef250d248c158f26129dd4dfab30845d07962fbfe7aa19b16db9
  • c38533b85e4750e6f649cc407a50031de0984a8f3d5b90600824915433a5e218
  • c7279a32329ebb1ab5c1cdbfbddb5a167e1505340c3ca72e837a222ff92665a6
  • cef161a220e019acc9ae79924a477c64aac2d6cc04126bb3f4a9f8452515f40f
  • d2645d16e869addd099727c3c58438c2f6935d92c00f9e4b237ef498de1dad87
  • dbed2ca2e9c53dd72c3ed3ce60e603c6c91c80152f924d97d8514781e6d9e26f
  • 185[.]61.154.26
download

Tip: 18 related IOCs (1 IP, 11 domain, 0 URL, 0 email, 6 file hash) to this threat have been found.

Overlaps

InfyThe Evolution of Infy: Cyber Espionage Campaigns Against Western Entities

Source: Checkpoint - February 2021

Detection (one case): 185[.]61.154.26

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Prince of Persia (Foudre v8) Malware Campaign

Security researchers have uncovered a new, highly undetected version of a malicious software program known as "Foudre." This malware is hidden inside a politically themed video file that installs the malicious program in the background while the user is watching the video.

The attack is part of an ongoing campaign called "Prince of Persia," which has been active for more than 10 years. Researchers believe the threat actors behind this operation are of Iranian origin.

The primary goal is cyber espionage and data theft. The malware functions as a remote access tool, meaning once it infects a computer, the attackers can secretly execute commands, steal saved passwords from internet browsers, and record the victim's keystrokes.

While the exact number of infected individuals is actively being investigated, the campaign is highly persistent. The attackers use a specialized algorithm to continuously generate new web addresses, allowing them to maintain long-term control over infected computers.

Rather than targeting large corporations or specific industries, this campaign is heavily focused on regular individuals. Based on the decoy video used—which protests the mandatory hijab—researchers believe the targets are predominantly Iranian citizens.

Victims are tricked into opening a downloaded archive file that appears to contain only a video. Once opened, the video plays to distract the victim while the malware secretly extracts itself, hides within the computer's system files, and establishes a connection with the attackers' servers.

Citizens who are interested in or involved with political and social movements are frequently targeted by state-aligned or regional groups. Attackers seek to monitor these individuals' communications, track their activities, and gather intelligence.

Individuals should be extremely cautious when downloading or opening compressed files, especially those containing unsolicited political or social media. Organizations should ensure their antivirus tools are updated to detect the newest version of this malware and monitor their networks for suspicious automated web traffic.

This is a highly targeted issue. The specific cultural context of the decoy video strongly suggests the attackers are focused entirely on a specific demographic in the Middle East, rather than attempting a widespread global infection.

About Affiliation
Prince of Persia
Prince of Persia is Intezer's campaign tracking name for continued Infy cluster operations documented from 2015 through at least 2025. The campaign represents the third documented evolution of the same Iranian surveillance infrastructure — following the original Infy malware and the Foudre rebuild — showing the group's sustained commitment to long-term espionage despite repeated public exposure. Prince of Persia campaigns target Iranian dissidents, opposition figures, and government officials using spear phishing with evolved malware families that incorporate improved anti-detection techniques, demonstrating the Infy cluster's operational longevity spanning nearly two decades.
View Prince of Persia's Insights