Malware
Tonnerre
- First Reported
- Mar 4, 2026
- Latest Reported
- Mar 4, 2026
Reported Context (1)
- SHA-256 hashes. Following recent campaign shifts, the group has been observed using updated Foudre and Tonnerre variants to target Iranian dissidents and regional government entities, leveraging Telegram-based C2 to Hunt.io Maps Infrastructure Linked to Iranian-Aligned Threat Actors
Malware (3)
Threat Actors (10)
MITRE ATT&CK (11)
Vendors (8)
Products (5)
Tools (3)
Industries (8)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.