Foudre is a Windows-based first-stage espionage malware family associated with the Iranian threat actor Infy, also known as Prince of Persia. Active in campaigns observed since 2017 and used in operations that trace back to the group’s earlier activity, Foudre functions primarily as a lightweight downloader, backdoor, and victim-profiling implant. Its role is to establish an initial foothold, collect basic host information, perform reconnaissance on the compromised system, and determine whether the victim merits deployment of a more capable second-stage implant, most notably Tonnerre.
Foudre has been delivered through targeted phishing lures, including Persian-language documents and fake Excel-themed archives, as well as malicious Office documents containing macros or embedded executables packaged as self-extracting archives. In later campaigns, the malware was also reported in document-based delivery chains using embedded executables rather than relying solely on macros. Once executed, Foudre installs on the victim host, communicates with attacker-controlled infrastructure, and can download and launch follow-on payloads.
The malware is notable for resilient command-and-control design. Multiple versions use a domain generation algorithm to locate active infrastructure and authenticate command-and-control servers through RSA signature verification, complicating sinkholing and impersonation by defenders. Reporting also indicates newer Infy operations paired Foudre-family tooling with Telegram-backed command-and-control workflows, reflecting an evolution in the group’s operational security and infrastructure flexibility.
Foudre’s directly observed capabilities include host reconnaissance, keylogging in some versions, persistence, and staged payload delivery. It has been described as sending basic system information to operators, recording keystrokes, and retrieving encrypted archives containing second-stage malware. In the broader Infy intrusion chain, Foudre serves as the scout component, while Tonnerre is deployed selectively for deeper surveillance and data theft. Victimology linked to these campaigns includes Iranian dissidents, regional government entities, civil society targets, diplomats, journalists, and organizations in countries including Iran, Turkey, Iraq, India, Canada, and parts of Europe. The malware family reflects a long-running, adaptive cyber-espionage program focused on selective targeting, stealth, and durable access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Infy sustained Foudre and Tonnerre variant operations with Telegram-based C2 targeting Iranian dissidents.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The second installation stage creates a link and runs its persistence mechanism: A scheduled task for helper.exe -ex <machine GUID in hex>.
The malicious document contains macros and an embedded rar sfx executable. When opened, the macros will run and will execute the embedded exe.
When the victim opens the document, a macro extracts the embedded package to the temp directory as fwupdate.temp and executes it after the document closes.
Finally, for command and control and exfiltration, Iranian-linked groups most commonly rely on application layer protocols (T1071), such as HTTP
A GET request is made to http://<cnc>//2016/?c=<computer_name>&u=<username>&v=<malware_version>&f=<base_folder>&mi=<machine_guid>&t=<time_string>
After connecting to the C2, Foudre downloads an encrypted self-extracting archive (SFX), and then decrypts and runs it... Tonnerre uses this C2 to... Download updates.
85 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware variant used by Infy with Telegram-based C2 targeting Iranian dissidents.
Malware variant used with Telegram-based command-and-control to target Iranian dissidents and regional government entities.
One of Infy’s core proprietary malware families used in its resurfaced espionage operations.
A named Infy-associated malware family referenced as being actively maintained/updated by the group.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.