Tonnerre Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 19, 2025
Last Seen
January 16, 2026

Tonnerre is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity January 16, 2026.

Overview

Tonnerre is a malware family attributed to the Iranian APT operation known as Prince of Persia. It forms part of a renewed PoP toolkit alongside other strains, used for espionage campaigns and linked to updates in Command-and-Control infrastructure. The emergence of Tonnerre within this campaign highlights ongoing state-sponsored cyber-espionage activity and rapid tool development.

Related Threat Clusters

Recent Intelligence Reports

  • Prince of Persia APT Analysis: Infy, Foudre, and Tonnerre Malware — Socprime · January 16, 2026
  • Iranian APT 'Prince of Persia' is back with three new malware strains — Scworld · December 31, 2025
  • Iranian APT Prince of Persia returns with new malware and C2 infrastructure — Csoonline · December 19, 2025

CVSS v3.1 Breakdown