Researchers reported that the Iranian-attributed Infy group, also known as Prince of Persia, resumed cyber-espionage operations with updated Foudre malware and a more capable second-stage backdoor called Tonnerre. The campaign used Persian-language lure documents and malicious archives containing a macro-enabled Word file and a disguised executable to infect Windows x86 and x64 systems, with Foudre v23 serving as the initial foothold before downloading or installing Tonnerre on selected higher-value targets. The activity followed earlier disruption efforts but showed the group had rebuilt its tooling and infrastructure.
Tonnerre expanded the operation beyond basic compromise by adding persistence, file theft, screenshot capture, optional microphone recording, remote command execution, and exfiltration over HTTP and FTP, while researchers also observed RSA-based server authentication, anti-analysis checks, and evolving DGA-based command-and-control infrastructure. Bitdefender said it sinkholed one Tonnerre domain and saw traffic from dozens of apparent victim IPs, indicating the campaign was still active, while Check Point and SafeBreach linked victim activity outside Iran, including organizations in Turkey such as a university and a state-owned investment bank. Earlier reporting from Unit 42 tied Infy to a decade of targeted attacks and documented the group’s transition from older Infy malware to Foudre, underscoring the continuity of the espionage operation.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
SafeBreach Labs and Check Point Research published findings on renewed Infy activity, highlighting updated Foudre malware and the second-stage payload Tonnerre. They also documented victim activity outside Iran, including two persistent targets in Turkey tied to a university and a state-owned investment bank.
During the first half of 2020, researchers observed new Foudre versions 20, 21, and 22 along with updated Persian-language lure documents and infection behavior. The lures used themes related to Mojtaba Biranvand and the ISAAR Foundation of Martyrs and Veterans Affairs.
Updated Foudre versions used a revised domain generation algorithm based on a CRC32 of the string format NRV1{year}{month}{weeknumber}. Check Point anchored the scheme's start date to December 27, 2018.
Check Point reported that Tonnerre version 10 had already appeared in Foudre 8. This showed the second-stage payload was integrated into the campaign by August 2018.
After reduced visibility following the takedown, Infy activity resumed through malware dubbed Foudre. Unit 42's 2017 reporting and Check Point's later retrospective both identify August 2017 as the return of the operation under this tooling.
Bitdefender identified a Tonnerre version 1 sample, indicating the second-stage malware had been in use since 2017. This pushed the known history of Tonnerre back earlier than later public analyses of newer versions.
Following its discovery work, Palo Alto Networks conducted a takedown operation against Infy's infrastructure. Check Point said the action caused Infy to lose access to almost all campaign victims.
Palo Alto Networks Unit 42 discovered and reported on the Infy malware operation, describing it as active in a decade of targeted attacks. Check Point later cited this 2016 discovery in its historical account of the campaign.
Research by Claudio Guarnieri and Collin Anderson linked the Infy operation to compromises of two Jundallah-related news websites. The activity was described as occurring as early as 2010 and involved exploiting ActiveX vulnerabilities on compromised sites to attack visitors.
Bitdefender analyzed a renewed Iranian-linked espionage campaign using Foudre version 23 and Tonnerre, and found the associated command-and-control infrastructure still active. The company sinkholed one Tonnerre domain and observed traffic from dozens of apparent victim IPs, indicating the operation remained ongoing at the time of reporting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 76 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
whisper.security
Open sourceresearch.checkpoint.com
Open sourceunit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceblackhat.com
Open sourcedownload.bitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.