Rugissement is an additional malware family associated with the Iranian espionage threat actor Infy, also known as Prince of Persia. Public reporting describes it as an older or previously unknown malware used in Infy campaigns prior to 2022, alongside tools such as Foudre, Tonnerre, Amaq News Finder, MaxPinner, and Deep Freeze. The available reporting does not provide a full technical profile for Rugissement, and explicitly characterizes it as unknown malware. High-confidence details indicate that Infy used it as part of a long-running and adaptable toolset in cyber espionage operations primarily targeting victims in Iran, with additional victims observed in Europe, Iraq, Turkey, India, and Canada. One reported behavioral detail is that MaxPinner checks whether Rugissement versions 16-17 or Tonnerre versions 12-18 are already installed on a victim machine and, if so, does not infect the host with MaxPinner. No specific infection vector, persistence mechanism, or standalone indicators of compromise for Rugissement are directly provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer proprietary Infy malware family added during the group’s renewed activity.
Rugissement is an older malware tool used by the Infy (Prince of Persia) APT group as part of their espionage toolkit.
Unknown malware referenced in the context of Infy (Prince of Persia) campaigns; details are not provided.
Rugissement is an additional malware family used by the Prince of Persia (Infy) group, observed in campaigns prior to 2022. Specific functionality is not detailed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.