Infy, also known as Prince of Persia and APT-C-07, is a long-running Iranian state-sponsored cyber-espionage threat actor active since at least 2004–2007. The group has conducted sustained surveillance and intrusion operations against government and private-sector targets across multiple continents, with especially strong focus on Iranian citizens, dissidents, journalists, diplomats, and regional government entities. Reported victim geography includes Iran, Iraq, Turkey, India, Canada, and parts of Europe, with earlier activity also observed against targets in Sweden and the Netherlands. Infy is best known for the Foudre and Tonnerre malware families, which have evolved through numerous versions over many years. Foudre has been used as a downloader and profiling component, while Tonnerre functions as a second-stage espionage implant for collection and exfiltration. More recent reporting also identifies a newer iteration called Tornado. The group has repeatedly modernized its tradecraft, including shifting infection vectors, introducing domain generation algorithms, validating command-and-control infrastructure with cryptographic mechanisms, selectively removing malware from lower-value victims, and frequently rotating infrastructure to reduce detection and disruption. The actor relies heavily on phishing and user-execution-based delivery, including malicious document lures and embedded executables. It has also been reported exploiting a WinRAR vulnerability to deliver Tornado through self-extracting archives. Infy has used both traditional HTTP-based command and control and Telegram-backed command channels, with Telegram also used for data exfiltration in later operations. Reporting additionally links the group to tooling that searches compromised systems for cryptographic keys and certificates, indicating post-compromise collection priorities aligned with credential access and follow-on espionage. Infy’s operations show persistent emphasis on defense evasion and operational resilience. Observed behaviors include parallel malware variants using different DGAs, staged infrastructure for victim validation and upgrades, selective victim handling, and adaptation to Iranian internet restrictions. Some reporting also attributes blockchain-based de-obfuscation techniques in Tornado to the group. Multiple assessments describe a definitive connection to the Iranian government and characterize Infy as one of the oldest known Iranian advanced persistent threat groups still in operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
“The threat actor is using a 1-day WinRAR vulnerability (likely CVE-2025-8088 or CVE‑2025‑6218) to extract Tornado to the startup folder.”
76 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named espionage actor associated with Tornado Malware and blockchain-based de-obfuscation techniques for state-level espionage.
Actor targeting Iranian dissidents using malware variants with Telegram-based command and control.
Iran-linked targeting of Iranian dissidents and regional government entities using updated malware variants and Telegram-based C2.
Referenced as a pre-existing actor involved in amplifying the conflict through credential/data theft and exploitation activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.