Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends
ID: 3508dc11-70bb-5abe-994c-c2af366ed0a6
STIX ID: report--3508dc11-70bb-5abe-994c-c2af366ed0a6
Feed Name: The Hacker News
SafeBreach and other researchers report that the Iranian APT known as Infy (Prince of Persia) resurfaced with new C2 infrastructure and updated tooling (Tornado v51, Foudre, Tonnerre) using HTTP and Telegram-based C2, a hybrid DGA/blockchain domain naming approach, and weaponization of a WinRAR 1-day flaw to deliver a self-extracting archive containing backdoor DLLs; investigators also recovered evidence linking ZZ Stealer and a malicious PyPI package used for exfiltration, indicating active, state-aligned espionage campaigns and several actionable IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
