Security researchers documented multiple Iran-linked intrusion campaigns that used spearphishing and staged malware delivery to target governments, industrial organizations, and Syrian opposition figures. Palo Alto Networks traced the Infy malware family to a long-running espionage operation active from 2007 through at least 2016, using malicious Word and PowerPoint files to install keyloggers, steal browser credentials, collect documents, and exfiltrate data from victims including government-related entities in Israel, the United States, and Denmark. Citizen Lab separately described Group5, an Iran-nexus operation that targeted Syrian opposition members with politically themed phishing emails and a watering-hole site, exploiting CVE-2014-4114 to deliver NanoCore, njRAT, and an Android DroidJack implant.
The campaigns combined custom tooling, commodity remote-access trojans, and operational infrastructure that pointed back to Iran. In the Group5 case, researchers tied the activity to an Iranian hosting provider, observed operator access from Iranian IP space, and found Persian-language development artifacts and crypter links, while the Infy operation was connected through shared infrastructure, malware strings, and a distinctive encoding scheme across more than 40 variants, including the more capable Infy M branch. Together, the reports show sustained espionage activity built on low-volume, highly targeted phishing, multi-stage malware chains, and surveillance-focused payloads aimed at credential theft, device monitoring, and data exfiltration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Menlo Security disclosed a malware campaign it named ISOMorph that uses HTML Smuggling to deliver ISO-based payloads leading to AsyncRAT/NJRAT infections. The report described delivery via email attachments and drive-by downloads, with payload hosting on Discord and defense evasion through reflective DLL loading and MSBuild.exe injection.
Citizen Lab published its report on the Group5 operation in August 2016, documenting spearphishing and watering-hole attacks against Syrian opposition members using NanoCore, njRAT, and DroidJack. The researchers assessed with moderate confidence that Group5 was likely a new Iran-nexus threat actor.
On July 26, 2016, Citizen Lab searched VirusTotal and found only 2 of 16 unique MD5s from the Group5 operation. The low detection footprint was cited as evidence that the campaign was highly targeted.
Citizen Lab reported that assadcrimes[.]info later moved back to a parked location on May 4, 2016. This marked the apparent end or abandonment of the watering-hole phase of the operation.
On 2016-05-02, Palo Alto Networks published research naming the previously unpublished malware family "Infy" and linking more than 40 variants to a decade-long targeted espionage campaign. The report assessed that the operation likely originated from Iran and targeted government and industrial organizations.
Palo Alto reported that attacks using the Infy malware family were still active as of April 2016. This showed the espionage campaign had continued for nearly a decade at the time of disclosure.
Citizen Lab found early site-development access to assadcrimes[.]info from Iranian IP address 37.137.131[.]70 beginning on October 11, 2015. The logs were part of the operational evidence supporting an Iran nexus for Group5.
After Al-Ameer replied asking for a working file, the operator sent a second malicious PPSX attachment, assadcrimes1.ppsx. The follow-up showed active operator engagement and adaptation during the spearphishing attempt.
On 2015-10-03, Syrian opposition figure Noura Al-Ameer received an email purporting to be from "Assad Crimes" with a malicious PPSX attachment themed around Iran killing pilgrims in Mina. Citizen Lab identified this message as the event that first exposed the Group5 operation.
Citizen Lab reported that the assadcrimes[.]info domain used in the Group5 operation was registered in June 2015. The domain was initially parked before later being used for a watering-hole campaign.
A PowerPoint file identical to one of the observed Infy phishing samples was uploaded to VirusTotal in May 2015 under the alternate filename "syria.pps." This provided another artifact linking the campaign's lure material to broader circulation.
In May 2015, Palo Alto WildFire detected malicious spear-phishing emails carrying files such as "thanks.pps" and "request.docx" sent from a compromised Israeli Gmail account to an Israeli industrial organization, and also observed the same Word lure sent to a U.S. government recipient. The emails delivered Infy malware through booby-trapped Office attachments.
Citizen Lab said the malware operation targeting Syrian opposition members was first discovered in late 2015 after analysis of the suspicious emails sent to Noura Al-Ameer. Follow-on monitoring then uncovered additional Windows and Android malware hosted on the same infrastructure.
The ages of some Infy command-and-control domains suggested malicious use as early as 2010. WHOIS records also tied six known C2 domains dating back to 2010 to the email address aminjalali_58@yahoo.com.
Researchers identified the oldest related Infy malware sample as dating to mid-2007, indicating the espionage operation had been active for years before public reporting. Palo Alto linked later variants back to this early sample through shared traits and infrastructure.
Historic registration data for the domain fastupdate[.]net suggested a possible malicious association tied to the Infy operation as far back as December 2004. Palo Alto cited this as the earliest infrastructure clue connected to the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcemenlosecurity.com
Open sourcemandiant.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.