Telegram for the throne.
ID: 5f625c6b-daed-5f85-83aa-efe7a4b816f8
STIX ID: report--5f625c6b-daed-5f85-83aa-efe7a4b816f8
Feed Name: The CyberWire
Threat Score
SafeBreach Labs' deep-dive into the Iranian-linked APT "Prince of Persia" finds the group remained active beyond 2022, uncovering new Foudre and Tonnerre malware variants, expanded campaign scale, active C2 infrastructure into late 2025, and a shift to Telegram-based command-and-control, providing sustained visibility and fresh IOCs into the group's evolving tooling and targeting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
