PULSE NAME
Whispering in the dark
WHITE BladedFeline AlienVault 2025-06-10 Modified: 2025-07-10
33
IOCs
MEDIUM VOLUME
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan.
Indicators of Compromise (13 / 33 total)
All FileHash-MD5 URL FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 01b99ff47ec6394753f9ccdd2d43b3e804f9ee36 2025-06-10
FileHash-SHA1 1c757accbc2755e83e530dda11b3f81007325e67 2025-06-10
FileHash-SHA1 272cf34e8db2078a3170cf0e54255d89785e3c50 2025-06-10
FileHash-SHA1 37859e94086ec47b3665328e9c9baf665cb869f6 2025-06-10
FileHash-SHA1 3d21e1c9dfba38ec6997ae6e426df9291f89762a 2025-06-10
FileHash-SHA1 4954e8ace23b48ec55f1ff3a47033351e9fa2d6c 2025-06-10
FileHash-SHA1 66bd8db40f4169c7f0fca3d5d15c978efe143cf8 2025-06-10
FileHash-SHA1 6973d3ff8852a3292380b07858d43d0b80c0616e 2025-06-10
FileHash-SHA1 73d0faa475c6e489b2c5c95bb51dede4719d199e 2025-06-10
FileHash-SHA1 b8afc21ef2aa854896b97f1c81b376dcdde2466d 2025-06-10
FileHash-SHA1 bb4ffcdbfad40125080c13fa4917a1e836a8d101 2025-06-10
FileHash-SHA1 e8e6e6afef3f574c1f5228bdb28abb34f8a0d09a 2025-06-10
FileHash-SHA1 f28d8c5c2283019e6ed788d20240abc8554cadb5 2025-06-10