Infy Hackers Resume Operations with New C2 Servers After Internet Blackout
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Iranian threat group Infy, also referred to as Prince of Persia, has resumed its cyber operations after a nationwide internet blackout imposed by Iranian authorities. The group ceased maintaining its command-and-control (C2) servers on January 8, 2026, coinciding with the start of the blackout. However, renewed activity was observed on January 26, 2026, when Infy established new C2 servers just a day before the Iranian government relaxed internet restrictions.
This resurgence in activity highlights the group’s state-sponsored nature, as it has been operating since 2004 with a focus on espionage and intelligence gathering. Recent reports from SafeBreach indicate that Infy has updated its malware, specifically the Tornado version 51, which employs both HTTP and Telegram for C2 communication. This change in tactics aims to enhance the flexibility and effectiveness of their operations.
Infy has also weaponized a one-day security flaw in WinRAR, identified as either CVE-2025-8088 or CVE-2025-6218, to extract the Tornado payload on compromised hosts. The malware uses specially crafted RAR archives to bypass security measures, indicating a sophisticated approach to cyber attacks.
In addition, the group has introduced a new DGA algorithm for generating C2 domain names, which allows for greater flexibility in registering domains without needing to update the Tornado version. This innovative method reflects the group’s adaptability in the face of cybersecurity defenses.
SafeBreach’s analysis revealed that Infy has been using a Telegram bot for command and control purposes, allowing them to issue commands and collect data from compromised systems. The use of Telegram demonstrates the evolving nature of cyber threats, as attackers leverage popular communication platforms to facilitate their operations.
The implications of Infy’s activities extend beyond individual targets, as their operations align with Iran’s broader strategic interests. Organizations and individuals should remain vigilant against potential cyber espionage and be aware of the evolving tactics employed by state-sponsored hacking groups.
- Infy (Prince of Persia): An Iranian threat group that has resumed operations with new C2 servers after the internet blackout.
- Tornado: The latest version of Infy’s malware, which uses both HTTP and Telegram for command and control.
- CVE-2025-8088: A security flaw in WinRAR exploited by Infy to extract malware payloads.
- Telegram bot: A tool used by Infy for issuing commands and collecting data from compromised systems.
- DGA algorithm: A method employed by Infy to generate C2 domain names flexibly.
Key Takeaways
- Regularly update software to protect against known vulnerabilities like CVE-2025-8088.
- Monitor network traffic for unusual activity, especially related to Telegram communications.
- Educate employees about the risks of malware and phishing attacks that may exploit popular applications.
- Implement robust endpoint security solutions to detect and mitigate malware threats.
- Conduct regular security audits to identify and address potential weaknesses in your systems.
Key Terms & Concepts
- Infy: In this article, Infy refers to an Iranian threat group involved in cyber espionage and operations aligned with state interests.
- C2 servers: C2 servers are command-and-control servers used by hackers to manage compromised systems and execute commands.
- Tornado: Tornado is the latest version of malware used by Infy, employing both HTTP and Telegram for communication.
- CVE-2025-8088: CVE-2025-8088 is a security vulnerability in WinRAR that Infy has exploited to deliver malware.
- DGA algorithm: A DGA algorithm is a method used by attackers to generate domain names for command-and-control servers.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.