Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations
Iranian state-sponsored threat actors, known as "Prince of Persia," have initiated a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks.
Iranian state-sponsored threat actors, known as "Prince of Persia," have initiated a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks.
The group, active since the early 2000s, has recently utilized updated malware variants to infiltrate systems and exfiltrate sensitive intelligence.
Their recent operations demonstrate advanced technical proficiency, employing novel evasion techniques and decentralized command-and-control (C2) infrastructures to circumvent modern security defenses.
The attackers employ malicious Microsoft Excel files containing embedded executables, representing a shift from their previous use of macro-enabled documents.
These files are disguised as administrative updates or regional news items to avoid standard antivirus detection.
Upon engagement, the malware drops a self-extracting archive that installs the Foudre backdoor, establishing a foothold within the compromised network.
Iranian state-sponsored threat actors, known as "Prince of Persia," have initiated a sophisticated cyberespionage campaign targeting global critical infrastructure and private networks.
SafeBreach analysts have identified renewed activity after a three-year dormant period, noting the group's transition to resilient operational security practices.
The research highlights the use of distinct malware families, Foudre and Tonnerre, which now feature advanced capabilities for persistence and data theft.
The operation is linked to a persona known as "Ehsan," indicating centralized management of the campaign's infrastructure.
Technical Analysis of Infection and C2 Communication
The campaign's sophistication is evident in the deployment of Foudre v34 and Tonnerre v50. Foudre v34 utilizes a multi-stage loading process involving a loader DLL named Conf8830.dll and a disguised DLL file d232 , masquerading as an MP4 video file.
Upon execution, the malware establishes persistence and communicates with C2 servers using a generated domain name. The Domain Generation Algorithm (DGA) calculates a CRC32 checksum based on a date-formatted string, transforming it into a unique hostname. The Tonnerre v50 variant introduces a redirection mechanism via Telegram, using a Telegram bot to receive commands.
C2 communication uses specific HTTP GET requests to validate victim machines, allowing attackers to selectively upgrade or remove infections while maintaining access to high-value targets.
The Foudre v34 sends a unique identifier to the server using this structure:
https://<c2 server>/1/?c=<machine name>&u=<user name>&v=<current version>
Based on reporting by Cyber Security News.




