Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Iranian APT Targeting Networks and Critical Infrastructure Organizations

Iranian state-sponsored threat actors, previously inactive, have re-emerged with advanced malware campaigns targeting critical infrastructure worldwide.

Iranian state-sponsored threat actors, previously inactive, have re-emerged with advanced malware campaigns targeting critical infrastructure worldwide.

According to a report by SafeBreach Labs, the "Prince of Persia" (Infy) Advanced Persistent Threat (APT) group has resurfaced after a three-year hiatus with enhanced operational security and tools.

The group, active since the early 2000s, went silent in 2022 following public exposure. Recent evidence indicates they used this period to retool. As of September 2025, they have deployed new malware variants, Tonnerre v50 and Foudre v34, in simultaneous campaigns.

A notable change in their tactics is the shift from traditional File Transfer Protocol (FTP) methods to using Telegram for Command and Control (C2) communication, leveraging the platform's encryption to evade detection.

The Tonnerre v50 malware redirects infected systems to a Telegram group named "سرافراز" (Sarafraz), meaning "Proudly." SafeBreach Labs has monitored the Prince of Persia group since 2019. Despite their apparent inactivity in 2022, research continued based on predefined anchors and patterns.

Iranian state-sponsored threat actors, previously inactive, have re-emerged with advanced malware campaigns targeting critical infrastructure worldwide.
Karim Nasrallah · The Levant Herald

The threat actors utilize a Telegram bot to command and exfiltrate data via the Telegram API. A specific user handle, @ehsan8999100, acts as an administrator alongside the bot, with activity recorded as recent as December 14, 2025. The use of a Persian name and consistent geolocation data supports the attribution to Iranian interests.

The group has updated its primary loader, Foudre v34, evolving from simple macro-laden documents to Microsoft Excel files containing embedded executables. These files, such as "Notable Martyrs.zip," are designed to bypass antivirus detection and deploy the malware payload.

The group employs complex Domain Generation Algorithms (DGA) to sustain resilient C2 infrastructure :

Tonnerre v50 uses an unknown DGA generating 13-character domains ending in .privatedns.org. Foudre v34 utilizes a two-step DGA, generating 10 or 12-character domains on TLDs like .site and .ix.tc.

Advertisement

"Testing" vs. "Production" Infrastructure

The investigation revealed a significant infrastructure network, differentiating between "testing" servers for development and "production" servers targeting actual victims. Security professionals are advised to monitor network traffic for the identified DGA patterns and unusual Telegram API requests. The "Prince of Persia" group is now more active and dangerous.

The scale of their activities is larger than previously estimated, with multiple concurrent campaigns. While most victims are Iranian dissidents, the group's targeting of global networks and critical infrastructure indicates an expanded focus. Researchers have mapped the group's C2 structure, providing defenders with critical Indicators of Compromise (IoCs) to counter these threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories