s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.persirai

📛 Threat Title

Malware family: Persirai

Category: Persirai First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.persirai`. Printable name: Persirai.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.persirai VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.persirai

IOC database

Type
domain
Value
elf.persirai
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.persirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.persirai

References (1)

Remediations (10)

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:github.com

    Jackskid carries legacy attribution markers from the Persirai (2017) and Torii (2018) IoT botnet families, shares technical similarities and C2 infrastructure with Aisuru, and exhibits strong naming and architectural ties to the CatDDoS derivative ecosystem that emerged from a late-2023 source code leak.

  • web:socprime.com

    Summary Prince of Persia (also tracked as APT-C-07) is a long-running Iran-aligned cyber-espionage actor assessed to be active since 2007. The group has cycled through multiple proprietary malware families—Infy, Foudre, Tonnerre, and MaxPinner—to surveil media organizations, political entities, and civil-society targets. Operations commonly blend spear-phishing with opportunistic drive-by ...

  • web:westoahu.hawaii.edu

    Persirai , the latest botnet family to take advantage of unsecured IOT devices, has overtaken Mirai as the most common webcam botnet, according to new research from the security software company Trend Micro. Persirai was found on 64% of IP cameras tracked by Trend Micro, more than double the number of the next most prevalent IP camera malware ...

  • web:www.csoonline.com

    Once considered dormant, the threat group has been quite active in evolving its techniques and tools, with updated malware for reconnaissance and data exfiltration.

  • web:www.picussecurity.com

    T1070.010 Indicator Removal: Relocate Malware In a Prince of Persia APT campaign, threat actors utilize a Self-Extracting Archive (SFX) file to initiate a cleanup routine that terminates the running Foudre process and immediately renames the underlying executable, thereby disabling its persistence mechanism to prevent the malware from reloading ...

  • web:www.rescana.com

    The Iranian advanced persistent threat (APT) group known as Infy (also referred to as "Prince of Persia") has re-emerged after a prolonged period of inactivity, orchestrating a new wave of cyber-espionage campaigns. Leveraging advanced malware variants and innovative command-and-control (C2) techniques, including the use of the Telegram messaging platform, Infy has demonstrated a significant ...

  • web:www.safebreach.com

    On December 18, 2025, we shared Part I of our most recent research project on the Iranian state-sponsored threat actor known as "Prince of Persia." SafeBreach Labs has followed this threat actor since 2019 and originally published research in 2021 that presented evidence they had dramatically reinforced their operations security activities, technical proficiency, and tooling capabilities.

  • web:www.sciencedirect.com

    Ceron et al. developed adaptive network layer techniques to improve the investigation and mitigation of IoT botnets, including the use of Mirai signatures to improve detection and response mechanisms. The network behavior of both Mirai and Bashlite samples was analyzed and scanned for botnet signature over a 24-hour period [88].

  • web:www.trendmicro.com

    A new IoT botnet called Persirai has been discovered targeting over 1,000 IP Camera models based on various Original Equipment Manufacturer (OEM) products.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.