Multiple reports detail Iranian-linked espionage activity and tooling updates. SafeBreach described follow-on findings on the Iranian state-sponsored actor “Prince of Persia,” including at least three active variants of Foudre and Tonnerre malware, newly identified C2 infrastructure, and a Telegram-based data exfiltration channel; after publication, the actor rapidly rotated C2 servers and Telegram accounts, attempted to obscure victim-tracking artifacts, and appeared to attempt a retaliatory action against researchers that resembled prior attacks against open-source Python libraries.
Separately, Plone (a Python-based CMS) reported it prevented a supply-chain compromise after an attacker used a stolen developer GitHub personal access token to force-push whitespace-obfuscated malicious JavaScript into multiple repositories; the changes were detected before any official release, and GitHub assessed the payload was intended to compromise other developers (persistence via shell startup scripts, RCE, and theft of credentials/API keys/browser profiles/crypto wallet files). Additional Iranian activity was reported in an espionage campaign attributed to APT42 (IRGC-linked) using TAMECAT, a modular, largely in-memory PowerShell backdoor delivered after prolonged social engineering (e.g., WhatsApp rapport-building), with modules for browser data theft, screenshots, and file discovery; however, separate research on the Lazarus “Contagious Interview” campaign (fake job interviews and AnyDesk RAT backdoors) is unrelated to the Iranian-focused activity described elsewhere.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-04, SafeBreach published updated research describing newer Tornado/Tonnerre variants with HTTP and Telegram-based C2, new DGA and blockchain-based domain deobfuscation methods, suspected WinRAR 1-day exploitation, and links to ZZ Stealer and StormKitty activity. The report also released infrastructure details, Telegram artifacts, malware hashes, and other indicators of compromise.
Reporting published on 2026-02-04 attributed a targeted cyber-espionage campaign against senior defense and government officials to Iran-aligned APT42. The campaign used the modular fileless PowerShell backdoor TAMECAT, delivered through long-term social engineering and malicious links, with technical details on its loader, modules, and C2 methods disclosed.
Before any official release was made, Plone discovered that a threat actor had force-pushed obfuscated malicious JavaScript into five repositories using a compromised developer GitHub personal access token. Plone removed the code and hardened repository protections, including disabling risky Git operations such as force pushes.
On 2026-01-27, the nationwide blackout ended and the actor resumed activity using refreshed infrastructure. SafeBreach linked the operational pause and restart to the Iranian regime's network restrictions.
On 2026-01-25 and 2026-01-26, SafeBreach observed the group preparing and standing up new C2 servers. The timing correctly anticipated the end of the internet blackout and was cited as evidence supporting state sponsorship.
Starting on 2026-01-08, the group's activity paused as Iran's nationwide internet shutdown began. SafeBreach said the actor stopped maintaining its command-and-control infrastructure during the blackout.
Beginning on 2025-12-19, SafeBreach observed the actor replacing Telegram identities, rotating C2 servers and domains, and operating multiple active variants of its Foudre and Tonnerre malware. The changes appeared to be a response to public exposure and were accompanied by new evasion measures.
In December 2025, SafeBreach published Part I of its research on the Iranian threat actor known as Prince of Persia/Infy. The publication was followed by rapid changes in the actor's infrastructure and tradecraft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesafebreach.com
Open sourcenews.risky.biz
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.