logo

Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-IranTL-creat5161-en_EN:Bitdefender-PR-Whitepaper-IranTL-creat5161-en_EN.indd

ID: 6102fc7a-c086-4dee-be0e-52aed5a2113d

STIX ID: report--6102fc7a-c086-4dee-be0e-52aed5a2113d

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2021-02-19

Last Modified Date: 2021-02-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender researchers analyzed a decade-old Iranian APT known as Foudre and a new second-stage backdoor named Tonnerre: both delivered via malicious Office document and RAR SFX installers. The report details Foudre v23 and Tonnerre v11 capabilities — persistence, DGA-based C2, keylogging, screenshot and audio capture, targeted file collection and per-file encrypted archives for exfiltration — lists IOCs and C2 infrastructure, and reports sinkhole findings showing active callbacks from multiple IPv4/IPv6 hosts.