Skip to main content
Mallory
MalwareUsed by 1 actorExploits 2 CVEs

Tonnerre

Tonnerre is a custom second-stage espionage implant used by the Iranian threat actor Infy, also known as Prince of Persia. It is deployed after the Foudre downloader/profiler identifies a victim as high value, and is used for surveillance and data exfiltration from selected machines. Reporting describes Tonnerre as the heavier, more capable component of the Foudre/Tonnerre toolset, with multiple variants operating in parallel, including versions 12-18, 17, 50, and 51 (the latter also referred to as Tornado in some reporting).

Recent Tonnerre variants have evolved from older FTP-based exfiltration to Telegram-enabled command and control and data theft. Tonnerre v50 was observed in September 2025 and reportedly redirects victims to a Telegram group and bot, likely replacing older FTP-based exfiltration. The malware can use the Telegram API to send commands and retrieve victim data, and Telegram-based C2 is enabled only for select victims. SafeBreach reporting identified a Telegram group named "سرافراز" associated with this activity, with artifacts including a bot account and the user @ehsan8999100, and noted that Telegram group information was stored in a server-side file named tga.adr accessible only to specific victim GUIDs.

Tonnerre uses resilient C2 mechanisms. Multiple reports state that Infy runs at least three active Tonnerre variants in parallel using different DGAs. Tonnerre v17 uses the same DGA algorithm as Foudre v34 but with a different key prefix, FTS1. Broader reporting also states that Foudre and Tonnerre validate C2 domains using RSA signature files and public key cryptography, making sinkholing or C2 impersonation more difficult. Newer Tornado/Tonnerre variants reportedly support dual C2 over HTTP and Telegram, and one report states Tornado v51 also uses fixed names derived through blockchain-based domain deobfuscation in addition to a new DGA.

Observed infection chains place Tonnerre behind Foudre. Foudre is distributed via phishing emails and malicious Excel documents; more recent campaigns shifted from macro-laced Excel files to documents with embedded executables or self-extracting archives. Reporting also states the actor shifted initial access toward exploiting a WinRAR vulnerability, identified in sources as CVE-2025-8088 or CVE-2025-6218, to extract newer Tornado/Tonnerre-related payloads into Startup. Tonnerre has been associated with espionage campaigns targeting Iranian dissidents and regional government entities, with victims primarily in Iran and additional victims reported in Iraq, Turkey, India, Canada, and Europe.

Tonnerre is part of a broader Infy malware ecosystem that includes Foudre, MaxPinner, Amaq News Finder, Deep Freeze, and Rugissement. MaxPinner is described as a Telegram-focused spying trojan used in related campaigns. Operational reporting indicates Infy frequently rotates C2 servers, migrates valuable victims, deletes malware from low-value systems, and uses Telegram-based C2 to bypass defenses and adapt to Iranian internet restrictions. High-confidence infrastructure and operational details directly tied to Tonnerre in the reporting include Tonnerre v50/v51, Tonnerre v17, the FTS1 DGA prefix for v17, Telegram group "سرافراز," the user @ehsan8999100, and the tga.adr server-side artifact.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data StreamsExploited in the wild

“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”

via scworldscworld.com
CVE-2025-6218RARLAB WinRAR Directory Traversal Remote Code Execution VulnerabilityExploited in the wild

“Infy is also exploiting a zero-day vulnerability in WinRAR (CVE-2025-8088 or CVE-2025-6218) to deploy the Tornado payload.”

via scworldscworld.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Prince of Persia

Infy sustained Foudre and Tonnerre variant operations with Telegram-based C2 targeting Iranian dissidents.

via centripetal threat researchcentripetal.ai
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

T1071Application Layer ProtocolEvidence1

Finally, for command and control and exfiltration, Iranian-linked groups most commonly rely on application layer protocols (T1071), such as HTTP

T1568.002Domain Generation AlgorithmsEvidence1

“Prince of Persia… using a domain generation algorithm… multiple… variants of Foudre and Tonnerre using different DGA in parallel…”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.