PULSE NAME
Whispering in the dark
WHITE BladedFeline AlienVault 2025-06-10 Modified: 2025-07-10
33
IOCs
MEDIUM VOLUME
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan.
Indicators of Compromise (10 / 33 total)
All FileHash-MD5 URL FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6cc148363200798a12091b97a17181a1 2025-06-10
FileHash-MD5 1f1aaaf32be03ae7beb9d49f02de7669 MD5 of 6973d3ff8852a3292380b07858d43d0b80c0616e 2025-06-10
FileHash-MD5 66126dc088be2699fd55ae7eff5e6e15 MD5 of f28d8c5c2283019e6ed788d20240abc8554cadb5 2025-06-10
FileHash-MD5 6cc148363200798a12091b97a17181a1 MD5 of be0ad25b7b48347984908175404996531cfd74b7 2025-06-10
FileHash-MD5 7b62b055285b1c08e11ac98b3d3954bc MD5 of 1c757accbc2755e83e530dda11b3f81007325e67 2025-06-10
FileHash-MD5 a79e4424116dc0a76a179507ac914578 MD5 of 66bd8db40f4169c7f0fca3d5d15c978efe143cf8 2025-06-10
FileHash-MD5 b5de3c4c582db7c2d2ce31c67cba0510 MD5 of 272cf34e8db2078a3170cf0e54255d89785e3c50 2025-06-10
FileHash-MD5 b817309621e43004b9f32c96d52dc2a0 MD5 of 01b99ff47ec6394753f9ccdd2d43b3e804f9ee36 2025-06-10
FileHash-MD5 d56b5fd6b8976c91d2537d155926afff MD5 of bb4ffcdbfad40125080c13fa4917a1e836a8d101 2025-06-10
FileHash-MD5 fb164cdf119b0d4427bdcb51b45075b1 MD5 of 37859e94086ec47b3665328e9c9baf665cb869f6 2025-06-10