Iranian Infy APT Resurfaces With New Malware
The Iranian Infy APT resurfaces with new malware operations, breaking nearly five years of silence since its last known cyber campaigns. Security researchers at SafeBreach recently detected renewed activity linked to the Infy group, also known by the alias “Prince of Persia.” In its previous campaigns, the group targeted entities in Sweden, the Netherlands and Turkey with coordinated espionage efforts.
“This scale of Prince of Persia’s activity is more significant than we originally anticipated,” said Tomer Bar, SafeBreach’s vice president of security research. Analysts observed fresh threat indicators suggesting an expansion in either the group’s capabilities or its list of intended targets. The nature and sophistication of the new malware demonstrate that Infy has continued developing its attack infrastructure.
Analysts continue to track the group’s operations closely as concerns mount about possible impacts on regional cybersecurity. The Iranian Infy APT resurfaces at a time when state-backed hacking landscapes are growing increasingly complex.
https://thehackernews.com/2025/12/iranian-infy-apt-resurfaces-with-new.html
