TL;DR: Persistent adversaries can stay visible to defenders only when researchers track infrastructure, malware lineage, and operator behaviour together, according to SafeBreach. SafeBreach’s analysis shows Prince of Persia remained active through 2025, with multiple Foudre and Tonnerre variants, parallel DGA infrastructure, Telegram-based command channels, and exfiltration patterns that extend the group’s long-running APT campaign history.
At a glance
What this is: This is a SafeBreach analysis of a long-running Iranian nation-state APT group, with new findings on malware variants, command-and-control infrastructure, and exfiltration tradecraft.
Why it matters: It matters because persistent APTs increasingly mix malware, indirect command channels, and infrastructure churn in ways that break static detection, attribution, and response assumptions for network and identity teams.
By the numbers:
- Tonnerre v50 was detected as recently as September 2025 and uses an unknown DGA algorithm.
- The new Tonnerre v50 and Foudre version used C2 servers active between August 1, 2025 and September 20, 2025.
- SafeBreach researchers tracked Prince of Persia activity since 2019 and found no publicly identified activity for the next three years.
👉 Read SafeBreach's analysis of Prince of Persia's evolving malware and C2 activity
Context
Prince of Persia is best understood as a long-running APT campaign, not a single incident. The article shows how malware variants, command infrastructure, and operator behaviour evolve together, which is why static signatures rarely tell the full story. The primary security problem is defender visibility against a patient adversary that keeps changing transport, tooling, and delivery patterns.
The identity angle is indirect but real. Foudre and Tonnerre use malware staging, victim mapping, and exfiltration workflows that depend on credentials, machine identity, and trust in remote channels such as Telegram. That makes this relevant to IAM and NHI practitioners because offensive operators routinely exploit the same access assumptions that govern service accounts, device trust, and remote administration.
This is atypical in its level of longitudinal visibility. Most organisations do not maintain multi-year tracking across infrastructure shifts, malware refactoring, and operator retooling, which is exactly why these campaigns remain hard to contain.
Key questions
Q: Where does staged malware like Foudre fail in practice?
A: It fails when defenders detect the staging decision rather than the final payload. If teams flag macro-enabled delivery, embedded executables, deceptive archives, and the handoff from loader to second-stage malware, they can interrupt the chain before the operator reaches higher-value systems. That is more effective than waiting for the final binary to detonate.
Q: Why do DGA-based command channels make APT campaigns harder to contain?
A: DGA-based channels make containment harder because they let operators rotate destinations faster than static blocklists and many manual response workflows can keep up. Even when one server is taken down, the malware can continue resolving to fresh infrastructure. That forces defenders to hunt patterns, not just addresses.
Q: What do security teams get wrong about long-dormant APT groups?
A: They often treat silence as absence. In reality, a group can pause public visibility while refining tooling, shifting infrastructure, and testing channels that are harder to observe. The right response is to maintain dormant-actor watchlists and compare new detections against older infrastructure fingerprints.
Q: How should teams respond when malware uses Telegram for command and exfiltration?
A: They should treat it as a covert command-and-control path, not ordinary chat traffic. Focus on bot tokens, unusual group creation, suspicious endpoint-to-SaaS patterns, and file transfer behaviour that does not match business use. Containment should combine endpoint isolation with SaaS and proxy review before the operator can re-task the victim.
Technical breakdown
How Foudre and Tonnerre split the attack chain
The article describes a two-stage malware relationship. Foudre acts as the initial loader and environment mapper, then conditionally downloads Tonnerre when the victim is worth pursuing. That structure lets the operator reduce noise, reserve heavier tooling for selected systems, and adapt payload delivery without rebuilding the full chain each time. The campaign also shows repeated use of masquerading, embedded executables, and macro-enabled Excel files as delivery mechanisms. These are classic staging choices, but the key detail is the decision layer between first contact and escalation.
Practical implication: defenders need staging-aware detections, not just file-hash blocking.
What the DGA and C2 structure reveal about resilience
The malware families use domain generation algorithms to rotate command destinations and preserve reachability when individual servers are taken down or monitored. The C2 layouts also changed over time, with directory naming and validation logic varying by version. That matters because infrastructure churn is part of the actor’s resilience model, not an accident of implementation. The article shows older and newer servers coexisting, which indicates testing, production separation, and active iteration against defender pressure.
Practical implication: blocklists alone are insufficient when the adversary can swap domains and server layouts quickly.
Why Telegram changes the control problem
The newer Tonnerre variant redirects victims to a Telegram group and uses a bot token to issue commands and retrieve exfiltrated data. That shifts the operator’s control plane toward a third-party messaging platform, which complicates takedown, telemetry, and filtering. It also means the malicious workflow can hide inside ordinary SaaS traffic patterns unless teams inspect unusual bot activity, token use, and data movement tied to compromised endpoints. This is less about Telegram itself than about adversaries reusing legitimate trust channels for covert command exchange.
Practical implication: monitor sanctioned messaging services for bot-mediated command paths and abnormal token use.
Threat narrative
Attacker objective: The attacker aims to maintain long-term covert access, selectively deploy heavier payloads, and exfiltrate victim data while preserving operational flexibility.
- Entry begins with malicious Excel documents, macro-enabled files, or embedded executables delivered to the target and used to install Foudre as the first-stage loader.
- Escalation occurs when Foudre maps the victim, decides whether the host is worth pursuing, and then downloads Tonnerre or another second-stage payload for deeper control.
- Impact follows through command-and-control persistence, Telegram-mediated tasking, and exfiltration of victim files and metadata from active C2 infrastructure.
NHI Mgmt Group analysis
Persistent APT visibility is a governance problem as much as a detection problem. The article shows that an actor can appear dormant for years while continuing to adapt tooling and infrastructure underneath defender radar. That means the control failure is not only missed malware, but loss of continuity across campaigns, variants, and operator habits. For security teams, this reinforces the need for longitudinal threat intelligence and infrastructure correlation, not isolated alert handling.
Telegram-based command routing widens the trust boundary attackers can abuse. When malware shifts command and exfiltration into a mainstream messaging platform, the defensive question changes from ‘is this server malicious?’ to ‘which legitimate services are being repurposed for covert control?’ That is a more difficult policy and monitoring problem, especially where business use of sanctioned collaboration tools is normal. Practitioners should treat bot-mediated SaaS traffic as a control surface, not background noise.
Foudre and Tonnerre show the value of staged access decisions. The group does not spend heavier tooling on every victim. It maps, filters, and escalates selectively, which is a familiar pattern in advanced intrusion operations. The named concept here is selective payload escalation: the attacker preserves tooling, reduces detection exposure, and reserves higher-value malware for hosts that justify the risk. That is a reminder that containment must be designed around decision points, not just infection events.
Infrastructure churn is an adversary resilience strategy, not just a technical detail. The changing DGA logic, multiple active servers, and testing versus production split show a campaign that can absorb disruption and keep operating. This complicates attribution, hunting, and sinkholing efforts because the environment itself becomes part of the operator’s adaptation loop. For practitioners, the lesson is to prioritise infrastructure pattern analysis alongside content-based detections.
Identity assumptions still matter even in a malware-focused APT story. The campaign depends on victim selection, remote execution, and exfiltration paths that assume trusted endpoints and predictable operator access. Where defenders overtrust device state, admin pathways, or remote tooling, the adversary gains room to stage, pivot, and quietly persist. That makes this relevant to broader identity governance: machine trust, remote access, and privileged execution remain part of the attack surface even when the breach begins as malware.
What this signals
Selectively staged intrusion is the pattern to watch. Campaigns like this increasingly reserve heavier payloads for hosts that meet operator criteria, which means endpoint hygiene alone will not surface every intrusion decision. For practitioners, the programme signal is to pair sandboxing, identity-aware endpoint telemetry, and network correlation so that first-stage activity is visible before escalation completes.
Detection programmes should assume infrastructure churn is normal. When attackers rotate C2 layouts, use alternative command channels, and test servers alongside production ones, the security team needs hunt logic that survives domain changes. That means maintaining retrospective search capability across DNS, proxy, and endpoint data, plus mapping suspicious traffic to the service accounts and device identities that initiated it.
The broader governance implication is persistence, not novelty. The same operational lesson applies across malware, NHI abuse, and agentic automation: attackers succeed when defenders rely on static trust relationships and short memory. Teams that want durable resilience should compare current telemetry with known actor patterns and use OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls to anchor control selection.
For practitioners
- Track campaign infrastructure as a living graph Correlate C2 domains, DGA patterns, directory structures, and file hashes across months and years so that variant churn does not break the hunt. Use this to separate test servers from production infrastructure and to identify re-used operator patterns. This is the most direct way to preserve continuity across campaigns.
- Hunt for staged office-document delivery patterns Prioritise detections for Excel files with embedded executables, macro drops, self-extracting archives, and deceptive file icons or filenames. Those combinations often signal first-stage loader behaviour rather than routine document abuse.
- Inspect legitimate messaging services for covert tasking Review bot tokens, unexpected group membership, and abnormal exfiltration flows in sanctioned collaboration platforms such as Telegram when they are associated with suspicious endpoints. The goal is to identify command channels hidden inside normal SaaS traffic.
- Preserve telemetry for multi-year actor tracking Keep endpoint, proxy, DNS, and sandbox data long enough to compare present activity with older variants. This article shows that actor visibility improves when teams can compare current samples against prior infrastructure and malware behaviour.
Key takeaways
- Prince of Persia remains an active, adaptive APT campaign, not a historical case study.
- The most important defensive lesson is that long-lived adversaries combine staging, DGA churn, and alternative command channels to stay operational.
- Teams need multi-year infrastructure correlation and identity-aware telemetry if they want to spot repeat operators before the second stage lands.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 Initial Access; TA0006 , Credential Access; TA0010 , Exfiltration | The article tracks staged delivery, malware execution, and data theft across a multi-stage APT chain. |
| NIST CSF 2.0 | DE.CM-1 | Continuous monitoring is central to spotting infrastructure churn and covert command channels. |
| NIST SP 800-53 Rev 5 | SI-4 | System monitoring controls apply to malware behaviour, C2 activity, and exfiltration paths. |
| CIS Controls v8 | CIS-8 , Audit Log Management | Long-term actor tracking depends on durable logs for DNS, proxy, and endpoint review. |
Map delivery, execution, and exfiltration indicators to ATT&CK tactics and keep hunts aligned to stage progression.
Key terms
- Command and control infrastructure: The systems an attacker uses to send instructions to compromised hosts and receive data back. In malware operations, C2 is often built to survive takedowns, rotate domains, and hide inside normal network traffic so defenders cannot easily separate malicious from legitimate communication.
- Domain generation algorithm: A domain generation algorithm is code that creates many possible command-and-control domains, usually on a schedule or from seed values. It helps malware recover from server loss and frustrates blocklists because defenders must predict the next set of domains rather than block a fixed address.
- First-stage loader: A first-stage loader is the initial malware component that checks the environment, establishes a foothold, and decides whether to retrieve a more capable payload. It often keeps its behaviour light and selective so it can delay detection until the operator decides to escalate.
- Selective payload escalation: Selective payload escalation is an intrusion pattern where the attacker collects enough information from the victim to decide whether to deploy a second-stage tool. It reduces noise, preserves advanced malware for high-value targets, and complicates defence because not every infection follows the same path.
What's in the full report
SafeBreach's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step malware variant comparisons across Foudre v34, Tonnerre v17, Tonnerre v50, and related samples
- IOC tables for C2 servers, hashes, and DGA behaviour that help analysts extend their own hunts
- Exfiltration and Telegram bot details that show how the operator shifted command channels over time
- Timeline context for older campaign activity and the research anchors used to maintain visibility
👉 The full SafeBreach post covers malware variants, infrastructure details, and IOC appendices.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to broader security operations and governance.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org