Dormant No More: Iran’s “Prince of Persia” APT Resurfaces with Unmatched Stealth + Video

Listen to this Post

Featured Image
For years, cybersecurity experts believed Iran’s oldest advanced persistent threat (APT) group, “Prince of Persia,” had fallen silent. While other Iranian APTs like OilRig and MuddyWater dominated headlines, Prince of Persia seemed to vanish from the public eye. However, recent research has revealed that this elusive group has never stopped its operations. From spying on Iranian citizens to targeting individuals across Iraq, Turkey, India, Europe, and Canada, Prince of Persia has maintained a persistent and highly sophisticated cyber-espionage infrastructure for nearly two decades. Its resilience, operational security, and cryptographic command-and-control (C2) techniques set it apart from virtually every other known APT.

The Return of a Silent Threat

Known also as “Infy,” Prince of Persia first appeared in cybersecurity reports around 2004. Despite being one of the oldest state-level cyber threat groups globally—alongside APT1 and Turla—it remained largely invisible for years. Researchers noted sporadic activity until 2022, but recent investigations by SafeBreach confirm that the group has been quietly active, leveraging upgraded malware families to monitor dissidents and other targets across multiple continents. The group’s longevity is remarkable: nearly 20 years of fully operational cyberattack infrastructure without a significant lapse.

Advanced Tools: Foudre and Tonnerre

Prince of Persia’s success hinges on its custom-built malware tools. Foudre, a lightweight first-stage tool, collects system information to assess whether a target merits deeper intrusion. Its latest iteration hides within Microsoft Excel files and evades detection by all antivirus engines on VirusTotal. Tonnerre, the heavier secondary tool, handles extensive espionage tasks. Together, these tools demonstrate advanced stealth capabilities and unparalleled protection for C2 communications.

Foudre now employs RSA signature verification for C2 server authentication, generating 100 domains weekly via a domain generation algorithm (DGA). This mechanism ensures only the group’s private key, held exclusively in Iran, can validate C2 communications, effectively preventing researchers from hijacking servers or analyzing exfiltrated files. Tonnerre extends this stealth by using the Telegram API without embedding keys in its code, selectively targeting victims while keeping the infrastructure hidden.

State-Level Support and Resilience

Prince of Persia’s survival also highlights the unusual backing it receives from Iranian state entities. After Unit 42 of Palo Alto Networks exposed its infrastructure in 2016 and attempted a sinkholing takedown, the Iranian government’s Telecommunication Company intervened, redirecting traffic back to the attackers’ control. This extraordinary assistance allowed Prince of Persia to redesign its architecture, ensuring uninterrupted operations for years. Its sophisticated cryptography, DGAs, and private Telegram-based C2 channels now make it virtually untouchable by conventional countermeasures.

What Undercode Say: Advanced Operational Security Redefined

Prince of Persia exemplifies a rare level of operational security rarely seen even among nation-state actors. Its persistent presence over nearly two decades demonstrates the evolution of stealth and resilience in cyber espionage. Unlike louder APTs, Prince of Persia prioritizes undetectability over publicity, leveraging cryptography and dynamic C2 infrastructures to remain invisible.

The group’s use of RSA verification, selective key deployment, and advanced DGA implementation illustrates a paradigm shift in APT design. Traditional takedown strategies—sinkholing, domain hijacking, and malware reverse-engineering—prove largely ineffective against such architecture. Even expert researchers struggle to decrypt exfiltrated data or anticipate C2 channels without the private key, indicating a level of sophistication rarely seen outside high-budget state-sponsored campaigns.

This methodology also suggests strategic patience and prioritization. By focusing on high-value targets and employing triage mechanisms like Foudre’s initial reconnaissance, the group maximizes operational efficiency while minimizing exposure. Furthermore, its adoption of commonly trusted platforms, like Telegram, for covert communication highlights a growing trend: blending everyday digital tools with advanced malware to obscure detection.

The implications for global cybersecurity are significant. Prince of Persia’s long-term success demonstrates that even older, seemingly dormant APTs can silently pose severe risks. Organizations and governments must rethink detection strategies, moving beyond signature-based defenses and reactive measures. The resilience and adaptability of such groups underscore the urgent need for proactive, intelligence-driven cybersecurity approaches.

Fact Checker Results

✅ Prince of Persia remains active across multiple regions, as verified by SafeBreach.
✅ Its malware tools Foudre and Tonnerre use advanced cryptography and dynamic C2 techniques.
❌ Claims that Prince of Persia had been inactive since 2018 are outdated; it has been continuously operational.

Prediction

📊 Prince of Persia will likely continue to innovate, integrating AI-driven reconnaissance and automated evasion techniques.
📊 Regional espionage efforts targeting dissidents and political entities may intensify, with a growing focus on Europe and North America.
📊 Detection and mitigation will increasingly rely on AI-powered anomaly detection and cross-border intelligence sharing, rather than conventional antivirus solutions.

Prince of Persia demonstrates that in cyberwarfare, patience, precision, and stealth often outweigh volume and visibility, marking it as a model for the future of state-sponsored cyber operations.

▶️ Related Video (84% Match):

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon