Security1 distinct publisher2 min readPublished
Whisper Security's map of the Iranian espionage operation also turned up a working command server at 185.244.129.70 that no threat feed it checked lists. The staged domains will exploit the same blind spot when they switch on.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A domain with no address record gives blocklist tooling nothing to work with: passive DNS has no resolution to sample, and reputation scoring has no history to score. Whisper Security reports that a large pool of the group's domains sits in exactly that state, registered, with nameserver records pointing at machines the operators run themselves, and no A record anywhere [13]. Those nameserver-only boxes answer no malware and host no command service [12]. Activation is one record added on hardware the operators already control. No registrar contact, no new hosting order, no WHOIS event for anyone to notice.
The aging rate is measurable. SafeBreach published its second report on the actor in February 2026 [5]. By 13 August 2026, Whisper's expansion of those indicators through an infrastructure graph placed the group's servers across several blocks of a small Romanian reseller, AS204641 (HOSTGW), rather than the single range the reports named [1][8]. One of them, 185.244.129.70, carries the group's DGA domains, appears in neither SafeBreach report, and is listed in no threat-intelligence feed Whisper checked [9]. Roughly six months between publication and a documented gap in the published set [16].
The wiring explains why takedown leverage is thin. On the live servers, the domain, the address it resolves to, and the nameserver that answers the lookup are the same box: dmxqdlcuiryu.site resolves to 45.80.148.195, and ns1.dmxqdlcuiryu.site sits on 45.80.148.195; the .space domains on 45.80.149.3 are arranged the same way [11]. There is no third-party DNS provider in the path to send a complaint to.
Two limits on the finding. Whisper calls the inactive pool large but publishes no count, and gives no registration or activation dates [17], so the claim that the reserve expires blocklists on the operators' timing is structural rather than scheduled. And Whisper is explicit that "live" here means DNS-active, not confirmation that a server answers victims, which requires a direct connection it did not make [10].
The counterweight is that the enumeration is repeatable. Whisper identified the prepared domains using naming rules SafeBreach had already documented [14], which means a defender willing to run the rules does not have to wait for a vendor feed to catch up. That matters for who is being hit. Unit 42's 2016 write-up traced the campaign back to around 2007 against Iranian dissidents, journalists and opposition figures, with some government and telecommunications targets [3] - about nineteen years of continuous operation [15] against a population that mostly does not run a SOC. The current pairing, Foudre and Tonnerre, keeps a cheap first-stage profiler broad and reserves the second stage for targets the operators judge worth it [4].
Ranked by verification strength, evidence, and original report placement.
The server at 185.244.129.70 carries the group's DGA domains, sits in a block that appears in neither SafeBreach report, and is listed in no threat-intelligence feed Whisper checked; Whisper describes it as a working command server that reputation-based tools are blind to.
Whisper Security published a post mapping the backend infrastructure of Prince of Persia, authored by Kaveh Azarhoosh, Community & Research Lead, with all infrastructure data current as of 13 August 2026.
Prince of Persia is an Iranian espionage group that has been active for well over a decade, also tracked as Infy after the malware family that first exposed it.
Palo Alto Networks' Unit 42 documented the group in detail in 2016, describing a campaign reaching back to around 2007 that focused on Iranian dissidents, journalists and opposition figures, alongside some government and telecommunications targets.
The group's more recent tooling centres on two malware families, Foudre and Tonnerre, working as a pair: a first-stage implant that profiles a victim, and a second stage delivered only to targets the operators judge worth the effort.
SafeBreach has followed the group since 2019 and published two detailed reports in December 2025 and February 2026 covering the actor's return after a quiet period, its command-and-control servers, its domain-generation algorithm, and its move to Telegram for tasking.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher
product
Cloudflare turns OpenAI's cyber model into WAF rules that wait on human approval1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
science
Unit 42 counted 405 AI malware samples. Twelve reached a real endpoint.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise, self-reported, unchecked
Every technical assertion traces to one post by the firm that ran the queries: the reseller, the paired nameserver addresses, the unlisted 185.244.129.70. What lifts it above a vendor say-so is that the details are the falsifiable kind — named addresses, named domains, a named autonomous system, and a generator whose rules SafeBreach already published — so the work could be repeated and found wrong. What holds it down is that nobody in our record has repeated it, and the finding with the most operational weight is precisely the one requiring the most trust.
No usage signal in the record
Mapping infrastructure and anyone using the map are different things, and only the first appears here. Nothing tells us whether a feed has since added the address, whether any defender is blocking the HOSTGW blocks, or whether the delegated-but-unresolved hunting pattern has been adopted anywhere outside Whisper Security. We decline to read a demonstration as uptake.
Hedged body, unhedged promise
Whisper Security argues against itself more honestly than most vendors do — uneven graph coverage, 'live' meaning DNS-active only, the newest server not even fitting the pattern it is offered as proof of. The overreach is narrow and sits at the edges: 'a working command server' is a stronger word than DNS records can carry, and the promise that the staged domains will exploit the same blind spot when they switch on rests on a pool that is never counted and never dated. Modest overstatement, mostly in the framing rather than the findings.
The finding is also the product demo
Read the argument backwards and it is a capability pitch: reputation feeds missed a live server, our graph did not, and the same graph sees domains before they resolve. That is Whisper Security's own line of work, and the post's structure — indicator list as the naive baseline, graph as the fix — is shaped by it. Two things cut the other way: it credits SafeBreach for the reverse-engineering it did not do, and it prints the caveats that most weaken its headline. Strong interest, visibly disciplined.
Verifiable in principle, unverified in fact
We are reasonably sure what Whisper Security found and considerably less sure what it means. One publisher with a stake in the conclusion, no corroboration, no telemetry behind the word 'working', and a reserve of domains whose size sets the scale of the whole warning yet is never given. The addresses are concrete enough that this reads as a solid lead; treat the detection-gap conclusion as provisional until someone else resolves those names.