MaxPinner is a trojan associated with the Iranian threat actor Infy, also known as Prince of Persia. It is part of a broader, long-running malware toolkit used alongside Foudre, Tonnerre, Amaq News Finder, Deep Freeze, and Rugissement. The malware is described as Telegram-focused and is used to spy on Telegram content. Supporting reporting states that Foudre version 24 DLL downloads MaxPinner, and newer versions of MaxPinner were observed in 2021, including versions referred to as v5 and v8, with v8 assessed as developed in March 2021. MaxPinner is characterized as a Telegram-based trojan and Telegram data-focused malware. One report notes that MaxPinner checks whether Tonnerre versions 12 through 18 or Rugissement versions 16 through 17 are already installed on the victim machine and, if so, does not infect the host with MaxPinner. The malware is linked to Infy campaigns that primarily target victims in Iran, while also affecting entities in Europe, Iraq, Turkey, India, and Canada. High-confidence indicators directly mentioned in the content include references to malware hashes and IOC listings for "MaxPinner v5" and "MaxPinner v8."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...deploying a layered toolkit built around the Foudre, Tonnerre, and MaxPinner malware families alongside newer additions, including Amaq Finder and Rugissement.
1 distinct technique documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infy malware family used as part of a layered espionage toolkit.
Named tool/malware referenced only via IOC/hash listings; functionality not described in the provided content.
MaxPinner is an older malware tool used by the Infy (Prince of Persia) APT group as part of their espionage toolkit.
Trojan downloaded by Foudre to spy on Telegram content on infected machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.