Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-IranTL-creat5161-en_EN:Bitdefender-PR-Whitepaper-IranTL-creat5161-en_EN.indd
ID: 6102fc7a-c086-4dee-be0e-52aed5a2113d
STIX ID: report--6102fc7a-c086-4dee-be0e-52aed5a2113d
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2021-02-19
Last Modified Date: 2021-02-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender researchers analyzed a decade-old Iranian APT known as Foudre and a new second-stage backdoor named Tonnerre: both delivered via malicious Office document and RAR SFX installers. The report details Foudre v23 and Tonnerre v11 capabilities — persistence, DGA-based C2, keylogging, screenshot and audio capture, targeted file collection and per-file encrypted archives for exfiltration — lists IOCs and C2 infrastructure, and reports sinkhole findings showing active callbacks from multiple IPv4/IPv6 hosts.
