Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Prince of Persia’s malware tradecraft and C2 evolution: what changed?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Persistent adversaries can stay visible to defenders only when researchers track infrastructure, malware lineage, and operator behaviour together, according to SafeBreach. SafeBreach’s analysis shows Prince of Persia remained active through 2025, with multiple Foudre and Tonnerre variants, parallel DGA infrastructure, Telegram-based command channels, and exfiltration patterns that extend the group’s long-running APT campaign history.

NHIMG editorial — based on content published by SafeBreach: Prince of Persia, Part 1: A Decade of Iranian Nation-State APT Campaign Activity under the Microscope

By the numbers:

Questions worth separating out

Q: Where does staged malware like Foudre fail in practice?

A: It fails when defenders detect the staging decision rather than the final payload.

Q: Why do DGA-based command channels make APT campaigns harder to contain?

A: DGA-based channels make containment harder because they let operators rotate destinations faster than static blocklists and many manual response workflows can keep up.

Q: What do security teams get wrong about long-dormant APT groups?

A: They often treat silence as absence.

Practitioner guidance

  • Track campaign infrastructure as a living graph Correlate C2 domains, DGA patterns, directory structures, and file hashes across months and years so that variant churn does not break the hunt.
  • Hunt for staged office-document delivery patterns Prioritise detections for Excel files with embedded executables, macro drops, self-extracting archives, and deceptive file icons or filenames.
  • Inspect legitimate messaging services for covert tasking Review bot tokens, unexpected group membership, and abnormal exfiltration flows in sanctioned collaboration platforms such as Telegram when they are associated with suspicious endpoints.

What's in the full report

SafeBreach's full blog covers the operational detail this post intentionally leaves for the source:

  • Step-by-step malware variant comparisons across Foudre v34, Tonnerre v17, Tonnerre v50, and related samples
  • IOC tables for C2 servers, hashes, and DGA behaviour that help analysts extend their own hunts
  • Exfiltration and Telegram bot details that show how the operator shifted command channels over time
  • Timeline context for older campaign activity and the research anchors used to maintain visibility

👉 Read SafeBreach's analysis of Prince of Persia's evolving malware and C2 activity →

Prince of Persia’s malware tradecraft and C2 evolution: what changed?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Persistent APT visibility is a governance problem as much as a detection problem. The article shows that an actor can appear dormant for years while continuing to adapt tooling and infrastructure underneath defender radar. That means the control failure is not only missed malware, but loss of continuity across campaigns, variants, and operator habits. For security teams, this reinforces the need for longitudinal threat intelligence and infrastructure correlation, not isolated alert handling.

A question worth separating out:

Q: How should teams respond when malware uses Telegram for command and exfiltration?

A: They should treat it as a covert command-and-control path, not ordinary chat traffic. Focus on bot tokens, unusual group creation, suspicious endpoint-to-SaaS patterns, and file transfer behaviour that does not match business use. Containment should combine endpoint isolation with SaaS and proxy review before the operator can re-task the victim.

👉 Read our full editorial: Prince of Persia’s evolving C2 and malware tradecraft under the microscope



   
ReplyQuote
Share: