The Iranian state-sponsored threat group known as "Prince of Persia" or "Infy" has resurfaced after years of apparent dormancy, with new research revealing that the group has maintained continuous operations targeting dissidents and organizations both within Iran and internationally. Recent findings indicate that the group has upgraded its operational security, cryptographic communications, and malware arsenal, enabling it to persist undetected for nearly two decades. Victims have included Iranian citizens, as well as individuals and organizations in Iraq, Turkey, India, Europe, and Canada, with the group leveraging advanced variants of its established malware families such as Foudre and Tonnerre.
SafeBreach researchers have provided detailed technical analysis of the group's latest campaigns, identifying new malware versions and outlining indicators of compromise (IoCs) to aid defenders. The group's ability to remain active and effective for such an extended period is attributed to its sophisticated operational security measures and continuous evolution of its tools and techniques. This resurgence underscores the persistent threat posed by Iranian APTs to both regional dissidents and global critical infrastructure, highlighting the need for ongoing vigilance and updated defensive strategies.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On December 18, 2025, SafeBreach published research concluding that Prince of Persia remains active and has significantly evolved despite years of low visibility. The report detailed updated malware, infrastructure, attribution evidence, and indicators of compromise for defenders and law enforcement.
The group introduced stronger operational security, including Telegram-based command-and-control for some victims, frequent C2 rotation, and a domain generation algorithm protected by RSA-based validation. These changes made sinkholing and infrastructure impersonation more difficult for defenders.
During its renewed activity, Prince of Persia deployed updated Foudre and Tonnerre variants, shifted from macro-based Excel lures to Excel files with embedded executables, and used additional malware families and trojanized binaries. The changes improved evasion and helped maintain persistence on selected victims.
SafeBreach observed multiple new Prince of Persia campaigns over the past three years, showing the group had resumed significant cyber-espionage activity after an apparent lull. These operations targeted victims in Iran as well as Iraq, Turkey, India, Europe, and Canada.
SafeBreach researchers said they accessed stolen data because of a flaw in the attackers' file-naming convention, revealing victim data dating from 2021 onward. This indicates the group remained active during a period when public reporting was limited.
In 2016, Palo Alto Networks Unit 42 attempted to disrupt Prince of Persia operations. Dark Reading reports that Iran's state-owned Telecommunication Company of Iran allegedly helped the actor recover by blocking and redirecting traffic away from Unit 42 sinkholes.
SafeBreach and follow-on reporting describe the Iran-linked Prince of Persia (also known as Infy) espionage group as active since at least 2007. The group began a long-running campaign targeting dissidents, civil society, and other organizations, primarily tied to Iranian interests.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 71 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourcehackread.com
Open sourcesafebreach.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.