Prince of Persia: Infy Malware Active In Decade of Targeted Attacks
ID: 21d87b31-f628-4b0e-a55f-317fa03377a5
STIX ID: report--21d87b31-f628-4b0e-a55f-317fa03377a5
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2016-06-11
Last Modified Date: 2016-06-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Palo Alto Networks documents the 'Infy' malware family — a long-running, low-volume targeted espionage campaign (2007–2016) that used spear-phishing Word/PowerPoint attachments embedding multi-layer SFX executables to drop DLL payloads which implement keylogging, browser credential and cookie theft, screen and microphone capture, and remote C2-driven commands; the report includes sample analysis, a reusable string-decoding routine, C2 domain/IP/WHOIS correlations, IOCs, and attribution signals linking infrastructure to Iran.
