Infy, also known as Prince of Persia and APT-C-07, is a long-running Iranian state-sponsored cyber espionage threat actor active since at least the mid-2000s. It is widely regarded as one of the oldest publicly tracked Iranian advanced persistent threat groups. The actor has primarily conducted intelligence collection against government, diplomatic, private-sector, and civil-society targets, with a strong emphasis on Iranian citizens and dissidents, while also targeting victims across the Middle East, Europe, and other regions including Iraq, Turkey, India, Canada, Sweden, and the Netherlands. Infy is best known for sustained malware development and iterative operational refinement. Its historically associated malware ecosystem includes the Foudre downloader and profiler and the Tonnerre second-stage implant, along with newer variants such as Tornado. Reporting has also linked older tooling and related malware families such as Amaq News Finder, MaxPinner, Deep Freeze, and Rugissement to its operations. Recent activity shows continued parallel development of multiple Foudre and Tonnerre variants, use of evolving domain generation algorithms, staged command-and-control validation mechanisms, selective victim handling, and frequent infrastructure rotation to reduce detection and disruption. The group commonly relies on phishing and malicious document-based delivery, including lures using Office and PowerPoint files, and has adapted infection chains over time from macro-enabled content to embedded executables and self-extracting archives. It has been associated with exploitation of WinRAR vulnerabilities for malware delivery in more recent campaigns. Infy has also demonstrated post-compromise collection behavior consistent with espionage objectives, including searching infected systems for files related to cryptographic keys and certificates. A notable feature of Infy tradecraft is its persistent evolution of command-and-control methods. Earlier operations used more conventional infrastructure, while later campaigns incorporated Telegram-based command reception and data exfiltration, HTTP-based communications, and more resilient infrastructure designs. Some reporting also associates Infy with blockchain-based de-obfuscation or command-resolution techniques in Tornado, reflecting experimentation with harder-to-disrupt control channels. The actor has been observed using victim filtering, malware self-removal on lower-value systems, migration of victims between servers, and separate infrastructure paths for testing, upgrades, and operational victim management. Victimology and timing strongly support an Iranian intelligence mission. Infy has repeatedly targeted Iranian dissidents and regional government-related entities, and its operational behavior has been assessed as aligned with Iranian state interests. Public reporting has described a definitive connection to the Iranian government and characterized the actor as state-sponsored. Its activity patterns during periods of Iranian internet restriction have also been cited as consistent with coordination or support from within the Iranian state apparatus. Infy remains an active and adaptive espionage actor rather than a purely disruptive one. Its hallmark characteristics are long-term persistence, custom malware maintenance, careful operational security, social-engineering-led initial access, and steady modernization of exfiltration and command channels. Known aliases include Prince of Persia and APT-C-07.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
“The threat actor is using a 1-day WinRAR vulnerability (likely CVE-2025-8088 or CVE‑2025‑6218) to extract Tornado to the startup folder.”
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named espionage actor associated with Tornado Malware and blockchain-based de-obfuscation techniques for state-level espionage.
Actor targeting Iranian dissidents using malware variants with Telegram-based command and control.
Iran-linked targeting of Iranian dissidents and regional government entities using updated malware variants and Telegram-based C2.
Referenced as a pre-existing actor involved in amplifying the conflict through credential/data theft and exploitation activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.