Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Prince of Persia and the blackout effect: what defenders should watch


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A state-linked threat actor is replacing C2 infrastructure, hiding victim data, testing a Telegram-based exfiltration path, and attempting a strike-back using a ZZ Stealer loader while Iran’s internet blackout appears to have disrupted activity, according to SafeBreach. The case reinforces that operational visibility, not just signature coverage, is what lets defenders spot infrastructure churn, channel abuse, and attribution signals early.

NHIMG editorial — based on content published by SafeBreach: Prince of Persia, Part II, covering covering tracks, a strike-back attempt, and Tornado variant activity

By the numbers:

Questions worth separating out

Q: What breaks when attackers use trusted collaboration tools as command and exfiltration channels?

A: Security teams lose the separation between legitimate user communication and hostile operator activity.

Q: Why do infrastructure rotation and log tampering make incident response harder?

A: Because responders can no longer rely on a stable set of artifacts to reconstruct the campaign.

Q: What do security teams get wrong about malware families that keep changing names?

A: They often focus on the label instead of the behavior.

Practitioner guidance

  • Harden Telegram and other collaboration channels Review whether bots, forwarding permissions, private groups, and content protection settings could be abused for exfiltration or command delivery.
  • Build detections for infrastructure churn Track repeated domain generation, server rotation, certificate reuse, and transport changes across suspected campaigns.
  • Preserve independent forensic telemetry Retain logs from endpoints, network sensors, identity systems, and cloud controls so analysis does not depend on attacker-controlled communication logs or filenames.

What's in the full report

SafeBreach's full research covers the operational detail this post intentionally leaves for the source:

  • Appendix-level indicators of compromise for the Prince of Persia campaign and the updated Tornado family.
  • The ZZ Stealer decryption script and malware chain analysis used in the strike-back attempt.
  • The full Telegram workflow, including how the bot-forwarding path exposed historical messages.
  • The code and infrastructure notes behind the new C2 handling and victim-concealment logic.

👉 Read SafeBreach's analysis of Prince of Persia, Tornado, and the Telegram attack chain →

Prince of Persia and the blackout effect: what defenders should watch?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Operational concealment is now part of the attack surface. This campaign did not rely only on payload delivery. It actively removed logs, rewrote file metadata, and changed server behavior to make post-incident analysis harder. That means defenders must treat evidence preservation as a control objective, not an afterthought. When attackers can sanitize their own trail, the quality of independent telemetry becomes a decisive advantage.

A question worth separating out:

Q: How should incident teams respond when a threat actor may be operating during a blackout or network disruption?

A: Assume the pause may be temporary, not a stop. Teams should keep monitoring infrastructure regeneration, certificate issuance, and new domain registration so they can spot reactivation quickly. That helps avoid false confidence from a quiet period and prepares the organisation for renewed activity when connectivity returns.

👉 Read our full editorial: Prince of Persia shows how state actors cover tracks under blackout



   
ReplyQuote
Share: