Deep Freeze is a malware variant used in campaigns attributed to the Iran-linked APT group Infy, also known as Prince of Persia. In the provided reporting, it is described as an older Infy malware variant similar to Amaq News Finder and as part of a long-running, adaptable toolset that also includes MaxPinner and Rugissement. SafeBreach reported a Deep Freeze variant from 2019-2020 with the same structure as AmaqFinder, and assessed that it was probably used to infect victims with the Foudre malware. Deep Freeze was also observed in campaigns where related variants such as Amaq News Finder and MaxPinner v8 were used to spy on victims’ Telegram accounts. The broader Infy activity targeted victims primarily in Iran, with additional victims identified in Europe, Iraq, Turkey, India, and Canada, and focused on espionage against governments, organizations, dissidents, journalists, and diplomats. High-confidence associations in the content tie Deep Freeze to Infy/Prince of Persia operations and to delivery or support of Foudre in older campaigns; no standalone technical IOCs specific to Deep Freeze are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Deep Freeze is an older malware tool used by the Infy (Prince of Persia) APT group as part of their espionage toolkit.
Downloader malware similar to Amaq News Finder, used to infect victims with Foudre.
Deep Freeze is a loader malware variant used by Prince of Persia to deliver Foudre. It uses custom DGA algorithms and encrypted payloads, and was active in campaigns around 2019-2020.
Deep Freeze is a malware variant used by the Prince of Persia (Infy) group for espionage, specifically targeting Telegram accounts of victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.