Researchers Disrupt Iranian Cyberespionage Campaign | SecurityWeek.Com
ID: e51cf5f8-9cb9-49c8-8f93-a136db607e9b
STIX ID: report--e51cf5f8-9cb9-49c8-8f93-a136db607e9b
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2016-06-30
Last Modified Date: 2016-06-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Researchers at Palo Alto Networks disrupted an Iran-linked cyberespionage campaign using the 'Infy' malware family, sinkholing C2 domains and uncovering over 450 compromised agents on 326 systems across 35 countries; multiple variants exist (including the more capable Infy M), the malware primarily stole files (older variants recorded video) and continued evolving after disclosure. Although the campaign was largely shut down by domain takedowns, attackers changed infrastructure and released new variants, and researchers expect the threat actor may return.
