Iranian APT Targeting Networks and Critical Infrastructure Organizations
Iranian state-sponsored threat actors, previously inactive, have re-emerged with advanced malware campaigns targeting critical infrastructure worldwide.
Iranian state-sponsored threat actors, previously inactive, have re-emerged with advanced malware campaigns targeting critical infrastructure worldwide.
According to a report by SafeBreach Labs, the "Prince of Persia" (Infy) Advanced Persistent Threat (APT) group has resurfaced after a three-year hiatus with enhanced operational security and tools.
The group, active since the early 2000s, went silent in 2022 following public exposure. Recent evidence indicates they used this period to retool. As of September 2025, they have deployed new malware variants, Tonnerre v50 and Foudre v34, in simultaneous campaigns.
A notable change in their tactics is the shift from traditional File Transfer Protocol (FTP) methods to using Telegram for Command and Control (C2) communication, leveraging the platform's encryption to evade detection.
The Tonnerre v50 malware redirects infected systems to a Telegram group named "سرافراز" (Sarafraz), meaning "Proudly." SafeBreach Labs has monitored the Prince of Persia group since 2019. Despite their apparent inactivity in 2022, research continued based on predefined anchors and patterns.
Iranian state-sponsored threat actors, previously inactive, have re-emerged with advanced malware campaigns targeting critical infrastructure worldwide.
The threat actors utilize a Telegram bot to command and exfiltrate data via the Telegram API. A specific user handle, @ehsan8999100, acts as an administrator alongside the bot, with activity recorded as recent as December 14, 2025. The use of a Persian name and consistent geolocation data supports the attribution to Iranian interests.
The group has updated its primary loader, Foudre v34, evolving from simple macro-laden documents to Microsoft Excel files containing embedded executables. These files, such as "Notable Martyrs.zip," are designed to bypass antivirus detection and deploy the malware payload.
The group employs complex Domain Generation Algorithms (DGA) to sustain resilient C2 infrastructure :
Tonnerre v50 uses an unknown DGA generating 13-character domains ending in .privatedns.org. Foudre v34 utilizes a two-step DGA, generating 10 or 12-character domains on TLDs like .site and .ix.tc.
"Testing" vs. "Production" Infrastructure
The investigation revealed a significant infrastructure network, differentiating between "testing" servers for development and "production" servers targeting actual victims. Security professionals are advised to monitor network traffic for the identified DGA patterns and unusual Telegram API requests. The "Prince of Persia" group is now more active and dangerous.
The scale of their activities is larger than previously estimated, with multiple concurrent campaigns. While most victims are Iranian dissidents, the group's targeting of global networks and critical infrastructure indicates an expanded focus. Researchers have mapped the group's C2 structure, providing defenders with critical Indicators of Compromise (IoCs) to counter these threats.
Based on reporting by GBHackers.




