logo

Researchers Disrupt Iranian Cyberespionage Campaign | SecurityWeek.Com

ID: e51cf5f8-9cb9-49c8-8f93-a136db607e9b

STIX ID: report--e51cf5f8-9cb9-49c8-8f93-a136db607e9b

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2016-06-30

Last Modified Date: 2016-06-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Researchers at Palo Alto Networks disrupted an Iran-linked cyberespionage campaign using the 'Infy' malware family, sinkholing C2 domains and uncovering over 450 compromised agents on 326 systems across 35 countries; multiple variants exist (including the more capable Infy M), the malware primarily stole files (older variants recorded video) and continued evolving after disclosure. Although the campaign was largely shut down by domain takedowns, attackers changed infrastructure and released new variants, and researchers expect the threat actor may return.