Iranian hackers known as “Prince of Persia” are making a comeback with a new, highly sophisticated cyberespionage. According to recent analysis, the group is targeting critical infrastructure and private corporate networks globally, marking a clear escalation in both its strategy and technical prowess.

This particular threat is not new. The group has been active since the early 2000s, but its recent resurgence after years of relative inactivity is accompanied by new tools, techniques, and methods that make it significantly more difficult to detect and prevent.
From cyber espionage to digital persistence
The latestPrince of Persiareveal a mature approach to cyber operations. The group has developed upgraded malware variants designed for long-term persistence within compromised networks and for silent theft of sensitive data.
See also: Denmark accuses Russia of cyberattacks before elections
A particular emphasis is placed on avoiding detection, using decentralized command and control (C2) infrastructures, as well as new obfuscation techniques that bypass modern security solutions. This transition shows that attackers have carefully studied the defensive practices of target organizations.
New initial infection tactic via Excel
One of the most notable elements of the new campaign is the change in the initial infection method. Attackers are now using malicious Microsoft Excel that contain embedded executable files.
These files appear as innocent administrative updates or local and regional news, exploiting human curiosity and fatigue from constant security alerts. At the same time, they are designed to go unnoticed by traditional antivirus engines.

The installation of the Foudre backdoor
Once the victim interacts with the infected file, an infection chain is triggered that leads to the installation of the Foudre backdoor. The malware drops a self-extracting, which silently installs itself on the system, creating the attackers' initial "footprint" on the network.
See also: Hackers attacked the British government
Researchers at SafeBreach, who discovered the activity after about three years of relative silence, note that the group now uses two main malware families: Foudre and Tonnerre. Both have advanced persistence and data extraction capabilities.
Technical Analysis: Multi-level Loading and Smart C2
The technical sophistication of the campaign becomes more apparent in the latest versions Foudre v34 and Tonnerre v50. Foudre v34 leverages a multi-stage loading process, with a DLL loader (Conf8830.dll) executing a specific exported function. This, in turn, loads a second DLL, which is disguised as an MP4 video file, deceiving both users and automated security tools.
Once executed, the malware creates persistence mechanisms and initiates communication with C2 servers via dynamically generated domain names. The Domain Generation Algorithm (DGA) is based on dates and CRC32 calculations, generating unique host names, which makes it difficult to block communication.

Telegram as an attack management tool
The Tonnerre v50 variant introduces an even more unusual technique: using Telegram as a C2 intermediary. Instead of traditional protocols, the malware communicates with bots on Telegram to receive commands, taking advantage of the platform’s legitimacy and prevalence.
See also: LongNosedGoblin hackers use Windows Group Policy for attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The communication involves specific HTTP requests, through which data from the victim system. This allows attackers to precisely manage infections, upgrading or removing malware at will.
What does this mean for businesses?
The return of “Prince of Persia” highlights that state-sponsored threats are constantly evolving. For organizations that manage critical infrastructure or sensitive data, the threat is not theoretical. It requires ongoing user education, advanced threat detection, and a strategic defense that considers not only technology, but also the human factor.
