TL;DR: Persistent adversaries can stay visible to defenders only when researchers track infrastructure, malware lineage, and operator behaviour together, according to SafeBreach. SafeBreach’s analysis shows Prince of Persia remained active through 2025, with multiple Foudre and Tonnerre variants, parallel DGA infrastructure, Telegram-based command channels, and exfiltration patterns that extend the group’s long-running APT campaign history.
NHIMG editorial — based on content published by SafeBreach: Prince of Persia, Part 1: A Decade of Iranian Nation-State APT Campaign Activity under the Microscope
By the numbers:
- Tonnerre v50 was detected as recently as September 2025 and uses an unknown DGA algorithm.
- The new Tonnerre v50 and Foudre version used C2 servers active between August 1, 2025 and September 20, 2025.
- SafeBreach researchers tracked Prince of Persia activity since 2019 and found no publicly identified activity for the next three years.
Questions worth separating out
Q: Where does staged malware like Foudre fail in practice?
A: It fails when defenders detect the staging decision rather than the final payload.
Q: Why do DGA-based command channels make APT campaigns harder to contain?
A: DGA-based channels make containment harder because they let operators rotate destinations faster than static blocklists and many manual response workflows can keep up.
Q: What do security teams get wrong about long-dormant APT groups?
A: They often treat silence as absence.
Practitioner guidance
- Track campaign infrastructure as a living graph Correlate C2 domains, DGA patterns, directory structures, and file hashes across months and years so that variant churn does not break the hunt.
- Hunt for staged office-document delivery patterns Prioritise detections for Excel files with embedded executables, macro drops, self-extracting archives, and deceptive file icons or filenames.
- Inspect legitimate messaging services for covert tasking Review bot tokens, unexpected group membership, and abnormal exfiltration flows in sanctioned collaboration platforms such as Telegram when they are associated with suspicious endpoints.
What's in the full report
SafeBreach's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step malware variant comparisons across Foudre v34, Tonnerre v17, Tonnerre v50, and related samples
- IOC tables for C2 servers, hashes, and DGA behaviour that help analysts extend their own hunts
- Exfiltration and Telegram bot details that show how the operator shifted command channels over time
- Timeline context for older campaign activity and the research anchors used to maintain visibility
👉 Read SafeBreach's analysis of Prince of Persia's evolving malware and C2 activity →
Prince of Persia’s malware tradecraft and C2 evolution: what changed?
Explore further
Persistent APT visibility is a governance problem as much as a detection problem. The article shows that an actor can appear dormant for years while continuing to adapt tooling and infrastructure underneath defender radar. That means the control failure is not only missed malware, but loss of continuity across campaigns, variants, and operator habits. For security teams, this reinforces the need for longitudinal threat intelligence and infrastructure correlation, not isolated alert handling.
A question worth separating out:
Q: How should teams respond when malware uses Telegram for command and exfiltration?
A: They should treat it as a covert command-and-control path, not ordinary chat traffic. Focus on bot tokens, unusual group creation, suspicious endpoint-to-SaaS patterns, and file transfer behaviour that does not match business use. Containment should combine endpoint isolation with SaaS and proxy review before the operator can re-task the victim.
👉 Read our full editorial: Prince of Persia’s evolving C2 and malware tradecraft under the microscope