Iran's APTs and the U.S. Enterprise in 2026: Prince of Persia (Infy)
Post 4 of 5. How a group that has survived takedowns, sinkholes and dormancy since 2007 reinvents itself faster than the industry can publish on it, and why, when researchers finally mapped its live victims, the single most-targeted country outside Iran was the United States.
Published July 22, 2026

On January 8, 2026, Iran shut off the country's internet. The same day, Prince of Persia stopped maintaining its command-and-control servers. Two days before connectivity returned on January 27, the group was already registering new C2 domains pre-positioned for the moment Iran came back online.
If you read Post 3, the contrast is the point. APT42 is patient with people; Prince of Persia tracked by others as Infy and APT-C-07 is patient with time. It has run targeted espionage since at least 2007, been sinkholed, burned and driven dormant more than once, and returned every time with better operational security and new tooling. Exposure does not retire it; it retools and returns.
This post explains how a two-decade-old surveillance actor keeps coming back and why, when researchers finally mapped its live infrastructure in late 2025, the single most-targeted country outside Iran was the United States.
» Strengthen your cybersecurity with KELA's expertise
Who Is Prince of Persia (Infy)?
Its historical reputation is built on targeting Iranian dissidents, Persian-language press such as BBC Persian, civil-society activists, and diplomatic entities—the kind of victim list that lets a U.S. enterprise assume the group is someone else's problem.
That assumption no longer holds.
When SafeBreach Labs mapped Infy's live command-and-control infrastructure in late 2025, the victim set spanned more than 20 countries. The most heavily targeted country outside Iran was the United States, with 22 confirmed victims, ahead of Russia, Germany, and Nigeria.
A group whose brand is "surveillance of Iranian dissidents and Persian-language press" is now running a global espionage operation in which U.S. organizations are the single largest non-Iranian victim population.
- Prince of Persia (Infy) at a Glance
- Aliases: Prince of Persia, Infy, APT-C-07
- Operates from: Iran
- Sponsor / Backing: Iranian state, strongly assessed as regime-directed; no specific service has been publicly attributed. Historically shielded by state-controlled telecom infrastructure.
- Active since: At least 2007
- Ideology / motivation: Espionage, long-dwell data theft, and surveillance aligned to regime intelligence priorities. Historically focused on dissidents, the press, and the Iranian diaspora, the group is now broadening its focus to strategic foreign targets.
- Typical victims: Iranian dissidents, Persian-language press, civil-society activists, and diplomatic entities, with an increasingly global footprint led by the U.S. (22 victims), Russia, Germany, and Nigeria.
Signature Tactics, Techniques, and Procedures (TTPs)
- Multi-layer self-extracting archive (SFX) infection chains
- Foudre, Tonnerre, and Tornado malware families
- Blockchain-based domain generation
- Telegram API command and control (C2)
- Aggressive anti-researcher "strike-back" activity
Notable Activity (2025–2026)
- Foudre v34 and Tonnerre v50 with Telegram C2
- Tornado v51 blockchain DGA
- WinRAR vulnerability delivery
- ZZ Stealer strike-back against researchers
- C2 lifecycle synchronized to Iran's January 2026 internet blackout
The business impact is twofold.
First, Infy's tradecraft is built to defeat the controls most enterprises actually rely on domain blocklists and IOC feeds because its C2 domains are generated dynamically (now partly from the Bitcoin blockchain), and its command channel hides inside the legitimate Telegram API.
Second, the group has demonstrated a willingness to attack the people investigating it. Its 2025–2026 "strike-back" deployed an infostealer against security researchers, and its tooling overlaps with Iranian clusters known for poisoning open-source Python libraries.
A Global 1000 organization should care because Infy is both directly targeting U.S. organizations and treating the defensive community itself as a target. Its resilience also means that "we read the takedown report" is not the same as "we are no longer exposed."
» Understand how threat actors breach and exploit your data
A Two-Decade Campaign Arc
Infy's history is the clearest illustration in this series of an Iranian group that is judged on persistence rather than peak sophistication.
Early Operations (2007–2016)
The group ran highly targeted, low-volume spear-phishing designed to sit undetected for years. Its early focus was the U.S. government, Israeli industrial organizations, and Persian-language press such as BBC Persian, with activity spiking around the 2013 Iranian presidential elections.
When researchers sinkholed Infy's infrastructure in 2016, something telling happened: the Telecommunication Company of Iran actively blocked and redirected traffic to protect the group, an intervention that points strongly toward state sponsorship.
Malware Diversification (2017–2021)
Infy rebuilt around a multi-stage chain, debuting the Foudre downloader in 2017 and the Tonnerre second stage in 2018.
It tailored variants to specific lures: the Amaq News Finder, camouflaged as an ISIS news outlet, in 2017; a Deep Freeze variant in 2019–2020; and MaxPinner in 2021, which specifically spied on Telegram content.
Operations Coupled to Geopolitics
Infy's operational tempo tracks Iranian domestic and regional events closely.
During the 12-Day War (June 2025), exfiltration of victim files went quiet for roughly four months, consistent with a temporary shift in regime priorities.
More striking was the group's behavior around Iran's nationwide internet blackout of January 8–27, 2026. Infy stopped maintaining its C2 servers on the exact day the blackout began, then began registering new C2 domains two days before it ended, effectively pre-positioning for the restoration of Iranian connectivity.
That degree of synchronization with a state-imposed shutdown is, in KELA's assessment, hard to read as anything other than state coordination.
Latest Campaigns
After researchers surfaced new builds Foudre v34 and Tonnerre v50 that integrated the Telegram API for C2 (orchestrated through a Telegram group containing a bot and a user profile likely operated by an Iranian operator), Infy responded the way it always has: fast.
It replaced all active C2 servers, rewrote backend code to scrub victim IP addresses (substituting 0.0.0.0), and added RSA signature validation to lock researchers out.
It then deployed Tornado v51, capable of dual-protocol HTTP and Telegram communication.
Most aggressively, in a direct counter-move against investigators, the group planted a malicious ZIP inside its Telegram C2 channel disguised as a victim's exfiltrated data. Opening it dropped ZZ Stealer, a loader deploying a custom fork of the StormKitty infostealer onto the researchers' own machines.
» Here are the most targeted entry points by hackers
TTPs: How Prince of Persia Operates
Tradecraft summary
Three characteristics define how Prince of Persia (Infy) operates today, and together they explain why the group has remained effective for nearly two decades.
- First, it prioritizes resilience over novelty. Multi-stage malware, layered self-extracting archive (SFX) infection chains, and disciplined operational security allow the group to rebuild quickly when infrastructure is exposed or taken down.
- Second, it hides inside trusted infrastructure. Blockchain-derived domain generation, Telegram API-based command and control, and encrypted communications are designed to defeat traditional domain blocklists, IOC feeds, and reputation-based detection.
- Third, it is built for long-term surveillance. Rather than deploying disruptive payloads, Infy's tooling focuses on quietly collecting credentials, browser data, files, and user activity over extended periods while remaining difficult to detect.
The implication for defenders is straightforward: Static indicators and domain-based blocking will not reliably surface this actor. Detection has to move toward behavior, identity, and anomalous use of legitimate services.
APT34's tradecraft is best understood in five stages, with inline MITRE ATT&CK technique IDs hyperlinked to their canonical pages and the full mapping in the appendix.
1. Initial Access
Infy's traditional entry point is localized spear-phishing carrying weaponized Microsoft Word, Excel (macro-enabled) or PowerPoint attachments (T1566.001), and malicious links (T1566.002). The lures lean on social engineering, for example, mimicking a paused video to coax the user into executing the embedded payload.
2. Execution and Persistence
Infection relies on multi-layer self-extracting-archive (SFX) executables that drop loaders and DLLs disguised as benign files such as MP4s, executed as malicious files by the user (T1204.002) and driven through PowerShell (T1059.001) and the Windows command shell (T1059.003), with process injection used to run code under cover (T1055).
Persistence is established through:
The WinRAR delivery technique exists precisely to drop Tornado into the Startup folder.
3. Defense Evasion
The group's evasion is built around obfuscation and clean-up. Payloads are obfuscated and packed within the SFX layers (T1027) and decoded at runtime (T1140) the strike-back chain notably used PowerShell to XOR-decode executables.
Components masquerade as legitimate file types (T1036), and the group is unusually disciplined about removing its own traces (T1070).
Before proceeding, installers check for:
- Installed antivirus (for example, Avast)
Operators also issue automated "delete" commands via SFX updates to wipe Foudre from compromised machines once a host is no longer needed.
The earlier-mentioned scrubbing of victim IPs to 0.0.0.0 reflects the same instinct applied to their own infrastructure.
4. Command and Control, and Domain Generation
This is where Infy is genuinely ahead of most of its peers, and where conventional enterprise defenses struggle most.
The group runs HTTP/S-based C2 over web protocols (T1071.001) but layers two techniques on top that defeat blocklisting:
- Custom domain generation algorithms (T1568.002): Infy cycles C2 domains through custom multi-step domain generation algorithms. In a genuinely novel twist, Tornado v51 derives domains from raw Bitcoin blockchain transactions, reading specific scriptpubkey values and de-obfuscating hex strings under OP_RETURN and OP_PUSHBYTES fields to produce untraceable, attacker-controlled domains.
- Telegram API abuse (T1102): The group uses the Telegram API as a C2 and exfiltration channel, using sendDocument and getUpdates to move stolen files and receive commands without touching traditional HTTP or FTP infrastructure.
Channel integrity is protected with asymmetric cryptography (T1573) via the RSA signature validation added during the latest retooling.
5. Credential Access, Collection and Exfiltration
Infy's implants are full-spectrum surveillance tools. They log keystrokes (T1056.001), capture screen and microphone data (T1113), harvest clipboard content (T1115), and extract saved passwords, auto-fill data and cookies from Chrome, Edge, Firefox and Opera (T1555.003).
Hosts are profiled for system and network configuration (T1082, T1016) and local files are collected (T1005), aggregated and compressed into password-protected ZIP or RAR archives before exfiltration over the C2 channel (T1041) and over the Telegram web service (T1567).
» Here's everything you need to know about infostealers
Sectors and Victimology
Infy's targeting has historically been narrow and politically motivated: Iranian dissidents, Persian-language press members, civil-society activists, and diplomatic entities, concentrated in regions such as Denmark, Israel and the United States.
The recent picture is materially different and is the reason this post leads with the U.S. Analysis of Infy's live C2 servers revealed at least 46 distinct victims across more than 20 countries. Outside Iran, the most heavily targeted country was the United States (22 victims), followed by Russia (21), Germany (18) and Nigeria, with further infections across Europe, Canada, India and Southeast Asia. A group whose brand is "diaspora surveillance" is now running a global espionage operation in which US organizations are the single largest non-Iranian victim population.
KELA assesses Infy as a state-directed entity. The synchronisation of its C2 lifecycle with the January 2026 internet blackout, combined with the documented history of Iranian telecom providers shielding its infrastructure, is the basis for that attribution. The group's tooling and strike-back tradecraft also overlap with other Iranian clusters including the targeting of open-source Python libraries and activity associated with Educated Manticore indicating a shared ecosystem in which intelligence, tooling and infrastructure move between Iranian state-aligned units.
Three Takeaways for the U.S. Enterprise
1. The Victim Data Puts You at the Top of the List
Treat distance as irrelevant. Infy's own live infrastructure shows the U.S. as the most-targeted country outside Iran.
The historical framing of this group as a diaspora-and-press surveillance actor undersells the current risk to U.S. organizations of strategic value. If your threat model exempts Iranian "dissident-focused" actors on the assumption they won't touch a U.S. enterprise, that assumption is contradicted by the group's current footprint.
2. Your Domain and IOC Controls Are Exactly What This Group Is Built to Evade
Blockchain-derived DGA and Telegram API C2 are designed to defeat domain blocklists and signature feeds.
Detection has to move to behavior, including:
- SFX execution chains and DLLs masquerading as media files
- Payloads written into the user's Startup folder
- Anomalous use of the Telegram API (sendDocument / getUpdates) from non-user processes
- Credential-store and browser-cookie access by unexpected binaries
3. Your Hunt Team and Your Software Supply Chain Are Themselves in Scope
Infy's strike-back planting ZZ Stealer disguised as exfiltrated victim data and the cluster's history of poisoning open-source Python libraries mean two things for an enterprise.
- Researchers and incident responders handling suspected Infy artifacts should do so only in isolated, instrumented environments and assume that "captured" data may be bait.
- Dependency hygiene including provenance checks on Python packages and build-time scanning is part of defending against this actor, not a separate concern.
Coming Up in Post 5
The series closes with APT34 (OilRig), the most enterprise-focused of the four. Where Infy's reputation has lagged behind its true footprint, APT34's threat to U.S. organizations needs no reframing. It has already breached a U.S. government contractor (Westat), pairs long-dwell espionage with destructive wiper operations such as Shamoon and ZeroCleare, and has spent recent years burrowing into Exchange servers and domain controllers using password-filter DLLs and DNS tunneling.
If Prince of Persia is the actor that refuses to die, APT34 is the one that breaks things on the way out. That's where we finish.




