logo

Prince of Persia: Infy Malware Active In Decade of Targeted Attacks

ID: 21d87b31-f628-4b0e-a55f-317fa03377a5

STIX ID: report--21d87b31-f628-4b0e-a55f-317fa03377a5

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2016-06-11

Last Modified Date: 2016-06-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Palo Alto Networks documents the 'Infy' malware family — a long-running, low-volume targeted espionage campaign (2007–2016) that used spear-phishing Word/PowerPoint attachments embedding multi-layer SFX executables to drop DLL payloads which implement keylogging, browser credential and cookie theft, screen and microphone capture, and remote C2-driven commands; the report includes sample analysis, a reusable string-decoding routine, C2 domain/IP/WHOIS correlations, IOCs, and attribution signals linking infrastructure to Iran.