- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 921
The chain of coincidences turned out to be too neat to be accidental.

A recent SafeBreach Labs technical report shows how the activity of the Prince of Persia group changed immediately after the release of the previous report and how these changes coincided with the shutdown of the Internet in Iran. According to the company, monitoring the attackers' infrastructure allowed not only to track the evolution of their tools, but also to conclude that the campaign was directly linked to government agencies.
Tomer Bar from SafeBreach described the period from December 19, 2025 to February 3, 2026, when operators quickly replaced telegram accounts and management servers for the Foudre and Tonnerre families, as well as rebuilt domains, including addresses generated by the DGA algorithm. At the same time, the grouping tried to complicate attribution by clearing the logs, removing the IP addresses of the victims from the logs and substituting the value 0.0.0.0 in the names of the uploaded files.
The report describes a new modification, which SafeBreach calls Tornado version 51. It combines management via HTTP and Telegram, and can receive server domains in two ways: through DGA and through decryption of data from the blockchain, which gives operators flexibility without constantly replacing assemblies. For the initial infection, according to the authors, they began to use the latest WinRAR vulnerability to place the component in the startup folder.
A possible retaliatory strike against analysts is also described. A ZIP archive disguised as an upload from the victim was found in the message history of a Telegram group associated with the Prince of Persia. He started the chain with LNK and PowerShell and installed ZZ Stealer, which then loaded the modified StormKitty infostiler. SafeBreach notes strong coincidences with an incident in early 2024, when Python libraries with similar technology were compromised, as reported by Checkmarx. Additionally, there is a weaker link in terms of delivery methods with the Educated Manticore grouping, which was previously described by Check Point.
The key argument about the state nature of the campaign is related to the pause in the work of the infrastructure. SafeBreach has recorded the absence of new domain registrations and data uploads from January 8 to January 24, 2026, and attributes this to a nationwide Internet blackout in Iran. On January 26, server preparation activity resumed, and on January 27, the shutdown ended, which, according to the company, became an additional indicator of the dependence of operations on government decisions.
Thus, malicious campaigns should be evaluated not only by code and indicators, but also by their rhythm: when tools and infrastructure move synchronously with events in the real world, this turns into a signal that helps to better understand the sources of threats and strengthen protection in advance.

A recent SafeBreach Labs technical report shows how the activity of the Prince of Persia group changed immediately after the release of the previous report and how these changes coincided with the shutdown of the Internet in Iran. According to the company, monitoring the attackers' infrastructure allowed not only to track the evolution of their tools, but also to conclude that the campaign was directly linked to government agencies.
Tomer Bar from SafeBreach described the period from December 19, 2025 to February 3, 2026, when operators quickly replaced telegram accounts and management servers for the Foudre and Tonnerre families, as well as rebuilt domains, including addresses generated by the DGA algorithm. At the same time, the grouping tried to complicate attribution by clearing the logs, removing the IP addresses of the victims from the logs and substituting the value 0.0.0.0 in the names of the uploaded files.
The report describes a new modification, which SafeBreach calls Tornado version 51. It combines management via HTTP and Telegram, and can receive server domains in two ways: through DGA and through decryption of data from the blockchain, which gives operators flexibility without constantly replacing assemblies. For the initial infection, according to the authors, they began to use the latest WinRAR vulnerability to place the component in the startup folder.
A possible retaliatory strike against analysts is also described. A ZIP archive disguised as an upload from the victim was found in the message history of a Telegram group associated with the Prince of Persia. He started the chain with LNK and PowerShell and installed ZZ Stealer, which then loaded the modified StormKitty infostiler. SafeBreach notes strong coincidences with an incident in early 2024, when Python libraries with similar technology were compromised, as reported by Checkmarx. Additionally, there is a weaker link in terms of delivery methods with the Educated Manticore grouping, which was previously described by Check Point.
The key argument about the state nature of the campaign is related to the pause in the work of the infrastructure. SafeBreach has recorded the absence of new domain registrations and data uploads from January 8 to January 24, 2026, and attributes this to a nationwide Internet blackout in Iran. On January 26, server preparation activity resumed, and on January 27, the shutdown ended, which, according to the company, became an additional indicator of the dependence of operations on government decisions.
Thus, malicious campaigns should be evaluated not only by code and indicators, but also by their rhythm: when tools and infrastructure move synchronously with events in the real world, this turns into a signal that helps to better understand the sources of threats and strengthen protection in advance.