Tonnerre is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity January 16, 2026.
Tonnerre is a malware family attributed to the Iranian APT operation known as Prince of Persia. It forms part of a renewed PoP toolkit alongside other strains, used for espionage campaigns and linked to updates in Command-and-Control infrastructure. The emergence of Tonnerre within this campaign highlights ongoing state-sponsored cyber-espionage activity and rapid tool development.
The Iranian threat group known as Prince of Persia has re-emerged with three new malware strains targeting critical infrastructure globally. A December 2025 report from SafeBreach revealed that the group, which had been…
The Prince of Persia APT, also known as APT-C-07, has been active since 2007 and is linked to Iranian cyber-espionage efforts. This group employs various malware families, including Infy, Foudre, and Tonnerre, to target…