Infy APT Group Resurfaces with Updated Malware
Executive Summary
The Iranian threat actor Infy, also known as Prince of Persia, has resurfaced after a period of inactivity, targeting victims across Iran, Iraq, Turkey, India, Canada, and Europe. The group aims to conduct cyberespionage using updated versions of their Foudre and Tonnerre malware.
Key TTPs
- Initial Access: Phishing emails with macro-laced Microsoft Excel files or embedded executables to install Foudre.
- Execution: Exploiting embedded executables within documents to deploy malware.
- Defense Evasion: Using a domain generation algorithm (DGA) to make its command-and-control (C2) infrastructure more resilient and pivoting to Telegram for C2 communications.
Campaign Analysis
Infy has updated its malware variants, Foudre and Tonnerre, and shifted to using Telegram for C2 communications. The group's activity is more significant than previously anticipated, posing an ongoing risk to government and infrastructure networks.
Targeting & Infrastructure
- Target Profile: Victims across Iran, Iraq, Turkey, India, Canada, and Europe, including Iranian dissidents, government entities, and critical infrastructure organizations.
- Infrastructure: Utilizing multiple Domain Generation Algorithms (DGAs) and Telegram bots for command and control.
Relevant Terms
- APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign usually conducted by state-sponsored actors.
- DGA: Domain Generation Algorithm, an algorithm used to generate a large number of domain names that can be used for C2 servers, making it harder to block the communication.
Source: The Hacker News
