Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence

Nearly five years after the hacker outfit was seen targeting victims in Sweden, the Netherlands, and Turkey, threat hunters have discovered new behavior linked to an Iranian threat actor identified as Infy (also known as Prince of Persia).

In a technical analysis provided to The Hacker News, Tomer Bar, vice president of security research at SafeBreach, stated that Prince of Persia’s activity is larger than we first thought. This threat organization is still hazardous, relevant, and active.

According to a report published by Palo Alto Networks Unit 42 in May 2016 and co-authored by Bar and researcher Simon Conant, Infy is one of the oldest advanced persistent threat (APT) actors in existence, with evidence of early activity going all the way back to December 2004.

In contrast to other Iranian hacking groups like Charming Kitten, MuddyWater, and OilRig, the gang has also managed to stay elusive and garner little attention. The group’s attacks have mostly made use of two malware strains: Foudre, a downloader and victim profiler that installs Tonnerre read more about Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *