TL;DR: A state-linked threat actor is replacing C2 infrastructure, hiding victim data, testing a Telegram-based exfiltration path, and attempting a strike-back using a ZZ Stealer loader while Iran’s internet blackout appears to have disrupted activity, according to SafeBreach. The case reinforces that operational visibility, not just signature coverage, is what lets defenders spot infrastructure churn, channel abuse, and attribution signals early.
At a glance
What this is: This is a threat-actor analysis showing how Prince of Persia shifted infrastructure, obscured victim traces, and used Telegram-linked malware delivery under changing network conditions.
Why it matters: It matters to IAM and security teams because the same patterns that help attackers hide also expose gaps in telemetry, malware containment, and identity-linked command channels.
By the numbers:
- The researchers achieved access to more than 2,000 exfiltrated files in a two week period, providing detailed visibility into the group’s activity.
- The researchers recovered 118 files and 14 shared links from the threat actor’s Telegram group.
👉 Read SafeBreach's analysis of Prince of Persia, Tornado, and the Telegram attack chain
Context
Prince of Persia is a state-sponsored threat actor analysis focused on infrastructure churn, malware evolution, and operational concealment. The primary security problem is not only malicious code, but the way the group uses telemetry suppression, alternate channels, and short-lived infrastructure to reduce defender visibility.
For identity and access practitioners, the key intersection is the use of Telegram, exfiltration workflows, and compromised-host paths that depend on trusted channels and unmanaged runtime behaviour. That makes this relevant to NHI governance where service identities, secrets, and tool-mediated access can be abused to sustain attacker operations beyond the initial compromise.
Key questions
Q: What breaks when attackers use trusted collaboration tools as command and exfiltration channels?
A: Security teams lose the separation between legitimate user communication and hostile operator activity. That breaks detection assumptions, because malware traffic can blend with normal collaboration, and private groups or bots may still expose content through forwarding, API misuse, or weak content protection. Defenders need visibility into tool-level abuse, not just perimeter filtering.
Q: Why do infrastructure rotation and log tampering make incident response harder?
A: Because responders can no longer rely on a stable set of artifacts to reconstruct the campaign. When attackers replace C2 servers, delete logs, or rewrite metadata, they break the chain between observed traffic, victim identity, and operator intent. The result is slower containment, weaker attribution, and more dependence on independent telemetry sources.
Q: What do security teams get wrong about malware families that keep changing names?
A: They often focus on the label instead of the behavior. A renamed or recompiled family may still use the same delivery path, exfiltration pattern, and operator workflow. Defenders should anchor detections to transport methods, archive handling, and infrastructure lifecycle signals, because those are harder for the attacker to change without breaking operations.
A: Assume the pause may be temporary, not a stop. Teams should keep monitoring infrastructure regeneration, certificate issuance, and new domain registration so they can spot reactivation quickly. That helps avoid false confidence from a quiet period and prepares the organisation for renewed activity when connectivity returns.
Technical breakdown
Telegram as an exfiltration and control channel
Telegram can function as more than a messaging platform when attackers use bots, forwarded messages, and private groups to move data and instructions. In this case, the group’s behavior shows how a trusted communication service can become a covert transport layer for command and control, file retrieval, and operator coordination. The defender problem is not just blocking one application, but recognizing that legitimate platforms can carry malicious workflows without obvious malware-on-disk indicators. The key technical issue is that forwarding permissions and bot behavior can expose historic content even in private groups.
Practical implication: monitor suspicious Telegram API activity and review whether chat-forwarding, bot permissions, and content protection are adequately controlled.
How malware families evolve to preserve operational continuity
The article shows repeated changes to C2 servers, domain generation logic, and file-handling methods across Foudre, Tonnerre, and Tornado variants. That pattern is common when operators want resilience against takedowns and analysis, because each change can rotate infrastructure while preserving the same core workflow. The new Tornado variant adds dual protocols and a fresh naming strategy, which increases flexibility for operator re-use. From a defender’s view, the important signal is not the label of the family, but the persistence of the workflow across variants.
Practical implication: align detections to behaviours such as domain churn, alternate transport protocols, and repeated exfiltration patterns rather than single hashes.
Why victim concealment matters in threat operations
This campaign attempted to hide victim identity by removing logs, suppressing IP capture, and replacing real IP values with 0.0.0.0 in filenames. Those changes make attribution, triage, and incident reconstruction harder, especially when logs are already incomplete or short-lived. In operational terms, concealment is a control failure for defenders because it reduces the fidelity of forensic evidence and breaks correlations across telemetry sources. The more a threat actor can sanitize artifacts, the more defenders need independent logging and immutable evidence collection.
Practical implication: preserve independent telemetry sources so incident reconstruction does not rely on attacker-controlled logs or filenames.
Threat narrative
Attacker objective: The objective is to maintain resilient espionage operations while reducing the chance of detection, attribution, and disruption by defenders.
- Entry appears to have shifted toward a 1-day WinRAR vulnerability and malware delivery through archive-based execution paths, with Telegram used as a control and exfiltration layer.
- Credential or operational access was sustained through evolving C2 infrastructure, private groups, and file-forwarding workflows that let the operators retrieve data and issue commands.
- Impact included exfiltration, concealment of victim identity, and a suspected strike-back attempt using ZZ Stealer to infect researchers' machines.
Breaches seen in the wild
- Shai Hulud npm malware campaign — Shai Hulud campaign: npm malware exposed secrets on GitHub.
- Reviewdog GitHub Action supply chain attack — reviewdog/action-setup GitHub Action supply chain attack exposed secrets.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Operational concealment is now part of the attack surface. This campaign did not rely only on payload delivery. It actively removed logs, rewrote file metadata, and changed server behavior to make post-incident analysis harder. That means defenders must treat evidence preservation as a control objective, not an afterthought. When attackers can sanitize their own trail, the quality of independent telemetry becomes a decisive advantage.
Telegram abuse shows how trusted services become identity-adjacent infrastructure. The interesting issue here is not Telegram itself, but the way bots, forwarding, and private-group mechanics can support command and exfiltration workflows. That creates a governance problem similar to unmanaged non-human identity behavior: the service is legitimate, but the runtime use is not. Security teams should assume that trusted collaboration channels can be converted into operational control planes.
Named concept: telemetry suppression drift. This is the slow, deliberate erosion of defender visibility through log deletion, metadata manipulation, and infrastructure churn. It matters because many detection programs still assume that one platform or one log source will remain sufficiently intact to support investigation. In reality, attackers can degrade visibility in stages, so control design has to assume partial evidence and preserve cross-source correlation.
Infrastructure churn is a defensive signal, not just noise. Replacing C2 servers, changing domain generation logic, and pausing activity during the blackout all point to an actor that adapts to external pressure. For practitioners, that means anomalies in infrastructure lifecycle deserve more attention than isolated malware samples. The operational question is whether teams can track repeated patterns across domains, certificates, and delivery paths before the attacker re-establishes persistence.
The state-linkage matters because governance assumptions change. If the activity is linked to a regime, the response model has to account for patient operators, operational pauses, and deliberate concealment. That does not change the technical controls, but it does change the expectation of persistence and re-emergence. Incident handling should therefore prioritize durable evidence, repeatable detection, and campaign-level correlation over one-off containment wins.
What this signals
The practical signal for defenders is that campaign visibility now depends on stitching together collaboration telemetry, endpoint evidence, and infrastructure lifecycle data. A single security control will miss the actor’s changes, but cross-source correlation can still expose the pattern before the next rotation cycle completes.
Telemetry suppression drift: defenders should expect attackers to degrade evidence gradually rather than destroy it in one move. That means incident programmes need immutable logs, independent sensor coverage, and a correlation model that survives missing or manipulated artifacts.
For programmes that already monitor non-human access and service-to-service communication, this article is a reminder that identity-adjacent channels can be weaponised even when the payload is not an NHI credential theft case. The defensive posture should assume that trusted tooling, not only malware, can become part of the operator's control layer.
For practitioners
- Harden Telegram and other collaboration channels Review whether bots, forwarding permissions, private groups, and content protection settings could be abused for exfiltration or command delivery. Where collaboration tooling is part of the environment, log API use and alert on unusual forwarding activity or unexpected bot presence. Use content protection controls where operationally appropriate.
- Build detections for infrastructure churn Track repeated domain generation, server rotation, certificate reuse, and transport changes across suspected campaigns. The goal is to detect the workflow, not just one indicator hash, because the article shows that the actor can replace C2 servers quickly when exposed.
- Preserve independent forensic telemetry Retain logs from endpoints, network sensors, identity systems, and cloud controls so analysis does not depend on attacker-controlled communication logs or filenames. If a threat actor can erase or rewrite its own evidence, reconstruction must come from sources it cannot manipulate easily.
- Treat archive-based execution as a high-risk delivery path Increase scrutiny on archive files that unpack scripts or loaders into startup or execution paths, especially where public vulnerabilities are used to extract payloads. Pair content inspection with application control so suspicious archive chains are interrupted before execution.
Key takeaways
- Prince of Persia’s campaign shows that visibility loss is itself an attacker objective, not just a side effect of malware activity.
- The article documents infrastructure churn, log manipulation, and exfiltration at scale, which makes independent telemetry and cross-source correlation essential.
- Teams should harden collaboration tools, preserve immutable evidence, and detect behaviour patterns that survive domain and malware changes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement; TA0003 , Persistence | The article centers on actor tradecraft, infrastructure rotation, and stealthy operator workflows. |
| NIST CSF 2.0 | DE.CM-1 | The campaign depends on gaps in continuous monitoring and evidence quality. |
| NIST SP 800-53 Rev 5 | AU-6 | Attacker log deletion and metadata rewriting directly affect audit review and forensic reconstruction. |
| CIS Controls v8 | CIS-8 , Audit Log Management | The article highlights why log quality and retention are central to campaign reconstruction. |
| ISO/IEC 27001:2022 | A.8.15 | Monitoring activities and log evidence are directly relevant to this campaign’s concealment techniques. |
Map observed activity to ATT&CK tactics and prioritize detections for credential abuse, persistence, and movement.
Key terms
- Command And Control Channel: A command and control channel is a communication path an attacker uses to send instructions to compromised systems and receive results back. In cloud and AI workloads, that path can be built through legitimate services such as storage, APIs, or object exchange rather than direct network sockets.
- Telemetry Suppression: Telemetry suppression is the deliberate reduction, deletion, or distortion of security evidence so defenders cannot reconstruct what happened accurately. It includes log deletion, metadata rewriting, and hiding victim identifiers, all of which degrade investigation quality and slow containment.
- Infrastructure Churn: Infrastructure churn is the repeated replacement of domains, servers, certificates, or delivery paths to keep a campaign operational under pressure. It is a resilience tactic for attackers because it forces defenders to track behavior patterns rather than fixed indicators.
- Exfiltration Workflow: An exfiltration workflow is the process an attacker uses to move stolen data out of a victim environment and into attacker-controlled storage or channels. It often combines malware, messaging platforms, and staged retrieval so the operator can harvest data quietly over time.
What's in the full report
SafeBreach's full research covers the operational detail this post intentionally leaves for the source:
- Appendix-level indicators of compromise for the Prince of Persia campaign and the updated Tornado family.
- The ZZ Stealer decryption script and malware chain analysis used in the strike-back attempt.
- The full Telegram workflow, including how the bot-forwarding path exposed historical messages.
- The code and infrastructure notes behind the new C2 handling and victim-concealment logic.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, secrets management, and identity lifecycle control. It helps practitioners connect identity risk to the wider security programme they operate.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org