logo

Dormant Iran APT is Still Alive, Spying on Dissidents

ID: cb113e1c-7fe3-5a0b-8396-e5f988a26c29

STIX ID: report--cb113e1c-7fe3-5a0b-8396-e5f988a26c29

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

# Executive summary Prince of Persia (aka Infy) is a long-running Iranian state-linked APT active since ~2004 that remains operational and conducting espionage using updated malware families Foudre (lightweight first-stage) and Tonnerre (full-featured backdoor) which employ domain-generation algorithms, RSA-based C2 verification and selective Telegram API usage to resist detection, takedown, and analysis; SafeBreach's report documents continued targeting of Iranian citizens and individuals in Iraq, Turkey, India, Europe, and Canada and highlights apparent telecommunications/state support that preserved the actor's infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.