Geometric security barriers defending against Infy APT malware and ATM jackpotting.

Daily Cybersecurity News - December 21, 2025

Infy APT Group Resurfaces with Updated Malware

Executive Summary

The Iranian threat actor Infy, also known as Prince of Persia, has resurfaced after a period of inactivity, targeting victims across Iran, Iraq, Turkey, India, Canada, and Europe. The group aims to conduct cyberespionage using updated versions of their Foudre and Tonnerre malware.

Key TTPs

  • Initial Access: Phishing emails with macro-laced Microsoft Excel files or embedded executables to install Foudre.
  • Execution: Exploiting embedded executables within documents to deploy malware.
  • Defense Evasion: Using a domain generation algorithm (DGA) to make its command-and-control (C2) infrastructure more resilient and pivoting to Telegram for C2 communications.

Campaign Analysis

Infy has updated its malware variants, Foudre and Tonnerre, and shifted to using Telegram for C2 communications. The group's activity is more significant than previously anticipated, posing an ongoing risk to government and infrastructure networks.

Targeting & Infrastructure

  • Target Profile: Victims across Iran, Iraq, Turkey, India, Canada, and Europe, including Iranian dissidents, government entities, and critical infrastructure organizations.
  • Infrastructure: Utilizing multiple Domain Generation Algorithms (DGAs) and Telegram bots for command and control.

Relevant Terms

  • APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign usually conducted by state-sponsored actors.
  • DGA: Domain Generation Algorithm, an algorithm used to generate a large number of domain names that can be used for C2 servers, making it harder to block the communication.

DOJ Charges 54 in ATM Jackpotting Scheme

Executive Summary

The U.S. Department of Justice indicted 54 individuals linked to Tren de Aragua for deploying Ploutus malware in a large-scale ATM jackpotting scheme. The malware allowed the threat actors to remotely control ATMs and illicitly dispense cash.

The Scheme

  • TTP 1: Deploy Ploutus malware to compromise ATMs.
  • TTP 2: Exploit physical and software vulnerabilities to remotely control ATMs.
  • TTP 3: Force ATMs to dispense cash without legitimate transactions.

The Players

  • Threat Actor:Tren de Aragua (TdA)
  • Facilitators Arrested:54 individuals

The Consequence

  • Outcome: Defendants could face a maximum penalty of 20 to 335 years in prison if convicted.
  • Assets Seized/Forfeited:$40.73 million in losses since 2021.

Strategic Takeaway

The indictment highlights the increasing sophistication and global reach of cyber-enabled financial crimes, necessitating enhanced security measures for ATM infrastructure.

Relevant Terms

  • ATM Jackpotting: A scheme where criminals hack into ATMs, often using malware, to force them to dispense large amounts of cash.
  • Malware: Malicious software designed to disrupt, damage, or gain unauthorized access to a computer system.