logo

Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations

ID: 9ff04810-b5c6-5528-9418-9b7200003cff

STIX ID: report--9ff04810-b5c6-5528-9418-9b7200003cff

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Iranian state-sponsored APT "Prince of Persia" has reemerged with a global cyberespionage campaign targeting critical infrastructure and private networks using updated Foudre v34 and Tonnerre v50 backdoors delivered via malicious Excel files; technical analysis highlights loader DLL Conf8830.dll (export f8qb1355), a masqueraded DLL named d232, a two-phase DGA for C2 hostnames, and a Telegram-based command channel enabling persistent, selective control and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.