Iran's Prince of Persia cyber espionage group, also known as Infy, started to collect information before 2004 and has been active since then in the shadows, like many other older cybermanipulations from Tehran, such as Charming Kitten and MuddyWater. They are related to Iran and do not draw attention to themselves; instead, they use precision hits or laser-like precision for each of their long-term surveillance targets.
When researchers at SafeBreach were actively tracking this group, they noted that they stopped working right before the Iranian government imposed a national internet shutdown, which happened on January 8, 2026, after numerous protests due to remarkable economic instability.
For the first time in their monitoring, Infy's command-and-control (C2) servers went dormant, suggesting even state-backed operators couldn't (or chose not to) push through the restrictions.
Then, on January 26, right as authorities began easing the blackout, new C2 infrastructure popped up. It's a practical reminder: these groups' ops often mirror real-world events in Iran, reinforcing the assessment that Infy is state-sponsored.
Since mid-December 2025 through early February 2026, tracking this evolution shows that the group is tightening their tradecraft to avoid detection:
1. All C2 domain replacements for older malware types, Foudre (downloader/profiler) and Tonnerre (main implant).
2. Introduction of Tornado (Tonnerre v51), which supports dual C2 channels: classic HTTP plus Telegram bots for commands and exfil.
3. Tornado generates domains via a fresh DGA algorithm and by pulling/de-obfuscating fixed names from blockchain data ,a clever, flexible trick that avoids hardcoding and reduces the need for frequent malware updates.
Attack delivery has shifted too. Nfy now seems to exploit a 1-day WinRAR vulnerability (probably CVE-2025-8088 or the concurrent CVE-2025-6218, both path-traversal flaws were fixed in mid-2025 and are still exploited). Malware-laden RAR archives uploaded to VirusTotal in mid-December 2025 involved self-extracting (SFX) payloads:
1. AuthFWSnapin.dll → core Tornado v51 DLL
2. reg7989.dll → installer that checks for Avast AV (skips infection if present), sets up scheduled-task persistence, then runs the DLL
Once active, Tornado beacons over HTTP to download the full backdoor, grab system info, and exfiltrate. Telegram fallback uses bot APIs for stealthier ops. Older Tonnerre v50 tied to a group called "سرافراز" ("sarafraz," meaning proudly) with bot @ttestro1bot and user @ehsan8999100; v51 swaps in @Ehsan66442. SafeBreach even extracted messages from the private Telegram group, revealing exfil since February 2025, including 118 files and encoded commands.
A standout find: links to ZZ Stealer, a first-stage tool that profiles victims (env data, screenshots, desktop files), then on command "8==3" pulls and runs second-stage payloads. SafeBreach identified strong associations of ZZ Stealer groups with a malfeasance-ridden PyPI package ("testfiwldsd21233s") and also identified similar malfeasance occurring through the exfiltration of data by earlier variants of ZZ via Telegram. ZZ Stealer's association with Charming Kitten has a lower correlation (ZIP/LNK, PowerShell loaders), providing evidence of a potential shared toolset or inspiration within Iran's cyber ecosystem.
ZZ Stealer's consistent effort in evading detection (surviving sinkholes, sporadically changing methods of operation, and synchronizing operations with events within its own region of operation) serves as a reminder that many of the quietest actors are also the most persistent.
Finally, defenders should be alert to RAR file manipulation, odd Telegram bot activity at endpoints, unique scheduled tasks, and DGA-like domains as potential indicators of ZZ Stealer activity in high-risk geographic areas or industries; thus, layering situational awareness and instituting strict attachment protocols will be critical components to defending against ZZ Stealer.
Source: The Hacker News