top of page
Search

Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations

  • Dec 18, 2025
  • 1 min read

SafeBreach analysts identified this renewed activity after a three-year dormant period, noting the group’s transition to more resilient operational security practices.

Their research highlighted the group’s use of distinct malware families, Foudre and Tonnerre, which now feature advanced capabilities for persistence and data theft.

The investigation also linked the operation to a specific persona, “Ehsan,” suggesting a centralized and human-operated management of the campaign’s infrastructure.


Comments


Maverick Ventures Israel

Mindspace Rothschild, Rothschild Blvd 45, Second Floor

Tel Aviv, Israel 

© 2019 by Ventures Mavericks (Israel)

bottom of page