Prince of Persia: Infy Malware Active In Decade of Targeted Attacks - Palo Alto Networks BlogPalo Alto Networks Blog
ID: e62af4d5-cf1a-4824-baf7-d39fa7fe3a96
STIX ID: report--e62af4d5-cf1a-4824-baf7-d39fa7fe3a96
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2016-05-12
Last Modified Date: 2016-05-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 describes the 'Infy' malware family and a decade-long, targeted espionage campaign (2007–2016) that used spear-phishing Office/PPS attachments with embedded SFX executables to deploy DLL payloads; Infy and its 'Infy M' variant provide persistence, keylogging, browser credential and cookie theft, document/screenshot/microphone capture, remote command execution and exfiltration to multiple C2 domains, with observed IOCs and evidence suggesting origins in Iran.
