Infy, also known as Prince of Persia and APT-C-07, is an Iranian state-sponsored cyber-espionage group active since at least the mid-2000s. It has primarily targeted Iranian dissidents, journalists, diplomats, government entities, and private-sector organizations, while also conducting operations affecting victims in Iraq, Turkey, India, Canada, and Europe. The group conducts long-running surveillance and information-theft operations using the Foudre and Tonnerre malware families and newer Tornado variants. Its tradecraft includes malicious document-based delivery, exploitation of archive-handling vulnerabilities, scheduled-task persistence, domain-generation algorithms, selective victim validation, frequent command-and-control rotation, removal of malware from lower-value systems, and checks intended to evade security products and analysis. Infy has used HTTP and Telegram-based command-and-control, including Telegram bots for tasking and exfiltration. The group has also searched compromised systems for cryptographic keys and certificate material, which can support authentication abuse and collection of protected data. Its infrastructure and operational activity have periodically fluctuated, but the group has continued to develop malware variants and espionage capabilities after periods of reduced visibility.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
“The threat actor is using a 1-day WinRAR vulnerability (likely CVE-2025-8088 or CVE‑2025‑6218) to extract Tornado to the startup folder.”
76 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The group is discussed in connection with command-and-control infrastructure, including a newly identified server, dormant domains, and DNS indicators potentially signaling future C2 activation.
A named espionage actor associated with Tornado Malware and blockchain-based de-obfuscation techniques for state-level espionage.
Actor targeting Iranian dissidents using malware variants with Telegram-based command and control.
Iran-linked targeting of Iranian dissidents and regional government entities using updated malware variants and Telegram-based C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.