← Back to Pulse Feed
PULSE DETAIL
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
WhisperGate - S0689
PrimeCache
Shahmaran
Slippery Snakelet
Laret
Pinar
Flog
RDAT - S0495
Indicators of Compromise (10 / 33 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 6cc148363200798a12091b97a17181a1 | — | 2025-06-10 | |
| FileHash-MD5 | 1f1aaaf32be03ae7beb9d49f02de7669 | MD5 of 6973d3ff8852a3292380b07858d43d0b80c0616e | 2025-06-10 | |
| FileHash-MD5 | 66126dc088be2699fd55ae7eff5e6e15 | MD5 of f28d8c5c2283019e6ed788d20240abc8554cadb5 | 2025-06-10 | |
| FileHash-MD5 | 6cc148363200798a12091b97a17181a1 | MD5 of be0ad25b7b48347984908175404996531cfd74b7 | 2025-06-10 | |
| FileHash-MD5 | 7b62b055285b1c08e11ac98b3d3954bc | MD5 of 1c757accbc2755e83e530dda11b3f81007325e67 | 2025-06-10 | |
| FileHash-MD5 | a79e4424116dc0a76a179507ac914578 | MD5 of 66bd8db40f4169c7f0fca3d5d15c978efe143cf8 | 2025-06-10 | |
| FileHash-MD5 | b5de3c4c582db7c2d2ce31c67cba0510 | MD5 of 272cf34e8db2078a3170cf0e54255d89785e3c50 | 2025-06-10 | |
| FileHash-MD5 | b817309621e43004b9f32c96d52dc2a0 | MD5 of 01b99ff47ec6394753f9ccdd2d43b3e804f9ee36 | 2025-06-10 | |
| FileHash-MD5 | d56b5fd6b8976c91d2537d155926afff | MD5 of bb4ffcdbfad40125080c13fa4917a1e836a8d101 | 2025-06-10 | |
| FileHash-MD5 | fb164cdf119b0d4427bdcb51b45075b1 | MD5 of 37859e94086ec47b3665328e9c9baf665cb869f6 | 2025-06-10 |