Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations

Iranian state-sponsored threat actors, known as "Prince of Persia," have initiated a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks.

Iranian state-sponsored threat actors, known as "Prince of Persia," have initiated a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks.

The group, active since the early 2000s, has recently utilized updated malware variants to infiltrate systems and exfiltrate sensitive intelligence.

Their recent operations demonstrate advanced technical proficiency, employing novel evasion techniques and decentralized command-and-control (C2) infrastructures to circumvent modern security defenses.

The attackers employ malicious Microsoft Excel files containing embedded executables, representing a shift from their previous use of macro-enabled documents.

These files are disguised as administrative updates or regional news items to avoid standard antivirus detection.

Upon engagement, the malware drops a self-extracting archive that installs the Foudre backdoor, establishing a foothold within the compromised network.

Iranian state-sponsored threat actors, known as "Prince of Persia," have initiated a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks.
Leila Toufic · The Levant Herald

SafeBreach analysts have identified renewed activity after a three-year dormant period, noting the group's transition to resilient operational security practices.

The research highlights the use of distinct malware families, Foudre and Tonnerre, which now feature advanced capabilities for persistence and data theft.

The operation is linked to a persona known as "Ehsan," indicating centralized management of the campaign's infrastructure.

Technical Analysis of Infection and C2 Communication

The campaign's sophistication is evident in the deployment of Foudre v34 and Tonnerre v50. Foudre v34 utilizes a multi-stage loading process involving a loader DLL named Conf8830.dll and a disguised DLL file d232 , masquerading as an MP4 video file.

Advertisement

Upon execution, the malware establishes persistence and communicates with C2 servers using a generated domain name. The Domain Generation Algorithm (DGA) calculates a CRC32 checksum based on a date-formatted string, transforming it into a unique hostname. The Tonnerre v50 variant introduces a redirection mechanism via Telegram, using a Telegram bot to receive commands.

C2 communication uses specific HTTP GET requests to validate victim machines, allowing attackers to selectively upgrade or remove infections while maintaining access to high-value targets.

The Foudre v34 sends a unique identifier to the server using this structure:

https://<c2 server>/1/?c=<machine name>&u=<user name>&v=<current version>

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories