The invisible Iranian threat group known as Infy (also known as Prince of Persia) has evolved its tactics as part of its efforts to hide its tracks, while also preparing new command and control (C2) infrastructure to coincide with the end of the regime-imposed widespread internet shutdown earlier this month.
See also: MuddyWater uses malicious Word documents to distribute RustyWater

“The threat actor stopped maintaining its C2 servers on January 8th for the first time since we began monitoring their activities,” said Tomer Bar, vice president of security research at SafeBreach, in a report shared with The Hacker News.
The cybersecurity firm said it observed renewed activity on January 26, 2026, as the hacking group installed new C2 servers, a day before the Iranian government eased internet restrictions within the country. The development is significant because it provides concrete evidence that the adversary is state-backed by Iran.
Infy is just one of many state-backed hacker groups operating from Iran that conduct espionage, sabotage, and influence operations that align with Tehran’s strategic interests. But it is also one of the oldest and least-known groups, having managed to stay under the radar, attracting little attention and operating quietly since 2004 through “focused” attacks targeting individuals to gather intelligence.
In a report published in December 2025, SafeBreach revealed new techniques associated with the threat vector, including the use of updated versions of Foudre and Tonnerre, with the latter likely using a Telegram bot to issue commands and collect data. The latest version of Tonnerre (version 50) has been codenamed Tornado.
See also: Iranian Prince of Persia hackers target critical infrastructure

Continuous monitoring of the threat actor's activities between December 19, 2025 and February 3, 2026 has revealed that the attackers have taken the step of replacing the C2 infrastructure for all versions of Foudre and Tonnerre, as well as introducing Tornado version 51 which uses both HTTP and Telegram for C2.
There is also evidence that Infy has exploited a daily vulnerability in WinRAR (either CVE-2025-8088 or CVE-2025-6218) to extract the Tornado payload to a compromised computer. The change in attack method is seen as a way to increase the success rate of its campaigns. The specially crafted RAR files were uploaded to VirusTotal in mid-December 2025, suggesting that the two countries may have been targeted.
Inside the RAR file is a self-extracting archive (SFX) containing two files:
– AuthFWSnapin.dll, the main DLL of Tornado version 51
– reg7989.dll, an installer that first checks if Avast antivirus software is not installed, and if so, creates a scheduled task for persistence and runs the Tornado DLL
Tornado establishes communication with the C2 server via HTTP to download and execute the main backdoor and collect system information. If Telegram is selected as the C2 method, Tornado uses the bot API to extract system data and receive more commands.
See also: MuddyWater targets Turkey-Israel-Azerbaijan with UDPGangster Backdoor

It is worth noting that version 50 of the malware used a Telegram group named سرافراز (literally translated as “sarafraz,” meaning proud) that included the Telegram bot “@ttestro1bot” and a user named “@ehsan8999100.” In the latest version, a different user named “@Ehsan66442” has been added in the latter’s place.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
