logo

Iranian APT ‘Prince of Persia’ Resurfaces With New Tools and Targets

ID: afb33b34-8220-5685-9e60-5de11eb66470

STIX ID: report--afb33b34-8220-5685-9e60-5de11eb66470

Feed Name: HackRead

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

SafeBreach Labs reports that the Iranian APT “Prince of Persia” (Infy) has re-emerged with expanded operations, using malware families Foudre (scout) and Tonnerre (payload), Domain Generation Algorithms, and Telegram-based command-and-control to target diplomats, activists, and critical systems globally; researchers recovered stolen files and observed variants spying on Telegram accounts, indicating an active, sophisticated espionage campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.