Tonnerre is a Windows second-stage espionage implant used by the Iranian threat actor Infy, also known as Prince of Persia. It is deployed after the Foudre first-stage malware identifies a victim as sufficiently valuable, and serves as the heavier collection and surveillance component in the group’s long-running cyber-espionage operations. Activity involving Tonnerre has been observed across multiple years and versions, including older FTP-enabled variants and newer builds that integrate Telegram-based command and control. Reported targeting has included Iranian dissidents, civil society, regional government entities, and selected victims outside Iran, including organizations in Turkey.
Tonnerre is associated with persistence, surveillance, remote tasking, and data theft. Documented capabilities include collecting files from user directories, removable media, logical and network drives; capturing screenshots; executing commands; interacting with the file system; compressing and transferring data; and optionally recording audio through the victim microphone. It has also supported command execution through an FTP-backed tasking channel in earlier variants. Persistence has been established through scheduled tasks, with fallback to a Run-key mechanism in some versions.
The malware has shown sustained evolution in command-and-control design and operational security. Earlier variants used a domain generation algorithm to locate HTTP infrastructure, validated servers using RSA signatures, exchanged metadata and updates over HTTP, and used FTP for command retrieval and exfiltration. Newer variants replaced or supplemented FTP with Telegram-based communications, allowing commands and victim data to be exchanged through Telegram infrastructure for selected victims. Multiple Tonnerre variants have reportedly operated in parallel, reflecting active maintenance and iterative development.
Tonnerre also incorporates defense-evasion measures. Reported behaviors include checks for specific security or system-management software before proceeding, selective enablement of Telegram functionality only for chosen victims, and infrastructure changes intended to reduce researcher visibility and hinder sinkholing or impersonation of command-and-control servers. Within the Infy toolkit, Tonnerre represents the principal post-compromise espionage implant used for deeper collection from high-value Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Infy sustained Foudre and Tonnerre variant operations with Telegram-based C2 targeting Iranian dissidents.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is a rar sfx password-protected exe, downloaded and executed by the initial Foudre backdoor.
This commands gets the list of antivirus products, firewall products, running processes, network adapters and uploads it to the ftp server
This commands gets the list of antivirus products, firewall products, running processes, network adapters and uploads it to the ftp server
The timer function: Collects files measuring between 1 byte and 8mb from the current user’s: Documents folder, Desktop folder, Download folder, Contacts folder, Pictures folder | Network drives • It looks only in same folders as for logical drives
<time_string> has this format: “<year>-<month>-<day>--<hour>-<minute>-<second>”
Steals files from predefined folders as well as external devices... Collects files from predefined folders – Documents, Downloads, Pictures and more.
Collects files from removable devices for exfiltration. This is done by monitoring WM_DEVICECHANGE messages and enumerating the devices.
Files are also collected from network shares using WNetOpenEnumW and WNetEnumResourceW functions from mpr.dll.
The files collected are archived (one archive per file) and the archives are saved in the “H” folder
Captures screen... Print screens are also collected if the screen saver is not active at the moment of checking.
If none of above cncs responded: <base_url> = md5(GET http://www.breakingnews.com/feeds/rss) ... <base_url> = md5(GET http://www.platts.com/rssfeeddetail/metals)
Finally, for command and control and exfiltration, Iranian-linked groups most commonly rely on application layer protocols (T1071), such as HTTP
A GET request is made to http://<cnc>//2016/?c=<computer_name>&u=<username>&v=<malware_version>&f=<base_folder>&mi=<machine_guid>&t=<time_string>
After connecting to the C2, Foudre downloads an encrypted self-extracting archive (SFX), and then decrypts and runs it... Tonnerre uses this C2 to... Download updates.
Then it uploads each collected archive measuring at least 100 bytes and maximum 8mb to the cnc
A POST request is made to http://<cnc>/blog/?<time_string> with the following body : c=<computer_name>&u=<username>&v=<malware_version>&f=<base_folder>&txt=<base64(archive_content)>&e=EOF
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware variant used by Infy with Telegram-based C2 targeting Iranian dissidents.
Malware variant used with Telegram-based command-and-control to target Iranian dissidents and regional government entities.
Core Infy malware family used in renewed state-sponsored operations.
A named Infy-associated malware family referenced as being actively maintained/updated by the group.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.