Infy is one of the longest-running Iranian espionage operations, documented by Palo Alto Unit 42 as 'Prince of Persia', active from around 2007 and using the custom Infy and later Foudre malware to conduct persistent surveillance of Iranian expatriates, dissidents, governments, and regional targets.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Infy was detailed by Palo Alto Networks Unit 42 in May 2016 ('Prince of Persia'), which traced the campaign's custom malware family back to roughly 2007 — making it one of the oldest continuously operating Iranian espionage efforts. After a 2016 disruption (sinkholing of its command-and-control), Unit 42 reported the actor's return in 2017 with a rebuilt toolset centered on the 'Foudre' backdoor. Attribution to Iran is medium confidence, based on Persian-language artifacts, victimology, and operational patterns; the group has no MITRE Group ID, flagged here.
The operation's tradecraft favored longevity and stealth over sophistication: spearphishing with weaponized Office documents (often bilingual Persian/English lures), self-updating implants, and resilient C2 designed to survive takedowns — as demonstrated by the actor's rapid rebuild after the 2016 sinkholing. The Infy and Foudre families provided document theft, keylogging, and remote command execution for sustained collection.
MENA relevance is strong. A large share of victims were Iranian — expatriates, dissidents, and individuals of interest to the state — reflecting a domestic-surveillance mission, alongside government and diplomatic targets in the region and beyond. The focus on Persian-speaking targets and Iranian émigrés situates Infy firmly within Iran's internal-security-oriented cyber apparatus.
Distinct Infy/Foudre activity has not been prominently re-reported since roughly 2017-2018, so the operation is assessed as dormant under this name. It is included as a foundational long-duration Iranian historical entry, flagged medium confidence and G-ID-less.