← Back to Pulse Feed
PULSE DETAIL
ESET researchers have uncovered a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has been targeting Kurdish and Iraqi government officials since at least 2017, using various malicious tools including reverse tunnels, backdoors, and a malicious IIS module. Key malware includes the Whisper backdoor, which communicates via compromised email accounts, and PrimeCache, a malicious IIS module with similarities to OilRig's RDAT backdoor. The campaign also targeted a telecommunications provider in Uzbekistan. BladedFeline's sophisticated tactics and tools indicate a focus on maintaining strategic access to high-ranking officials for espionage purposes.
MITRE ATT&CK & Malware Families
Indicators of Compromise (7)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 4cc88ce123b0da8d75c0fe66a39339f6 | — | 2025-06-06 | |
| FileHash-SHA1 | 562e1678ec8fdc1d83a3f73eb511a6dda08f3b3d | — | 2025-06-06 | |
| FileHash-SHA1 | be0ad25b7b48347984908175404996531cfd74b7 | — | 2025-06-06 | |
| domain | domain.computer | — | 2025-06-06 | |
| domain | olinpa.com | — | 2025-06-06 | |
| domain | zaincell.store | — | 2025-06-06 | |
| hostname | dropper.agent.gi | — | 2025-06-06 |