BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Iranian APT Group Infy Resurfaces with Advanced Malware Attacks

Infy (Prince of Persia) APT Resurfaces with Updated Malware Targeting Multiple Countries Using Advanced C2 and Telegram Integration

  • The Iranian threat group known as Infy or Prince of Persia has been found active again, targeting multiple countries including Iran, Iraq, Turkey, India, Canada, and parts of Europe.
  • The group uses updated versions of their Malware, Foudre and Tonnerre, mainly delivered via phishing emails and embedded files in Microsoft Excel documents.
  • Infy employs a domain generation algorithm (DGA) to secure their command-and-control (C2) infrastructure, validating domains daily using an RSA signature system.
  • The latest Tonnerre malware variant connects to a Telegram group for commands and data exchange, a novel approach in its operations.
  • Older malware variants, such as Amaq News Finder, MaxPinner, Deep Freeze, and Rugissement, have also been linked to this threat actor in past campaigns.

The Iranian cyber espionage group known as Infy or Prince of Persia has reemerged with new activity nearly five years after previously being detected targeting victims in Sweden, the Netherlands, and Turkey. This renewed campaign was uncovered by threat researchers in December 2025 and involves operations targeting countries such as Iran, Iraq, Turkey, India, Canada, and various European nations.

- Advertisement -

The group is notable for its long history, with evidence of operations dating back to 2004. It primarily relies on two malware strains: Foudre, a downloader and victim profiler, and Tonnerre, a second-stage implant used for data extraction on compromised machines. These malware versions have been updated, with the most recent Tonnerre variant detected as recently as September 2025. Infection often begins via phishing emails that deliver macro-laced Microsoft Excel files, which now embed executables to install Foudre.

A key feature of these attacks is the use of a domain generation algorithm (DGA) designed to enhance the resilience of their command-and-control (C2) systems. This algorithm produces daily unique domain names that Foudre verifies by downloading and decrypting RSA signature files to confirm the legitimacy of the C2 domain.

Analysis of the C2 infrastructure revealed specialized directories, including one named “key” for domain validation, another for communication logs, and others Hosting exfiltrated data. The most recent Tonnerre malware includes functionality to interface with a Telegram group named “سرافراز” (“proudly” in Persian). This group contains a Telegram bot (@ttestro1bot) believed to manage commands and data collection, alongside a user account (@ehsan8999100). The file storing this information is triggered only for specific victim identifiers.

Historical variants associated with the group include versions of Foudre disguised as a tool named Amaq News Finder, a trojan called MaxPinner used for spying on Telegram, a malware known as Deep Freeze, and an unidentified threat called Rugissement.

- Advertisement -

Despite appearing inactive in 2022, ongoing research emphasizes that Prince of Persia remains an active and sophisticated threat actor employing complex malware and operational security measures. For more detailed technical insights, refer to resources linked by SafeBreach and Palo Alto Networks Unit 42, as stated here and here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto Clarity Act Heads to Senate Committee Vote Thursday

The US Senate Banking Committee will vote on the CLARITY Act, a major crypto...

Exchanges lobby to ease crypto token listing rules in bill

Major U.S. cryptocurrency exchanges Coinbase, Kraken, and Gemini reportedly lobbied to remove restrictive language...

Brazilian Banking Trojan Targets Crypto Platforms

Cybersecurity researchers have uncovered a new Brazilian banking trojan named TCLBANKER, which targets 59...

Cloudflare stock plunges 20% on AI layoffs, soft guidance

Cloudflare stock plummeted over 20% on Friday despite reporting Q1 earnings that beat profit...

TeraWulf shares drop after $446M loss as AI shift grows

Publicly traded Bitcoin miner TeraWulf reported a Q1 2026 net loss of more than...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading