PULSE NAME
Whispering in the dark
WHITE BladedFeline AlienVault 2025-06-10 Modified: 2025-07-10
33
IOCs
MEDIUM VOLUME
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan.
Indicators of Compromise (8 / 33 total)
All FileHash-MD5 URL FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 068f5adf9c87d0b3fa8a37056042e76139bb230a9fd559028eb13cdf360ebbaa SHA256 of 6973d3ff8852a3292380b07858d43d0b80c0616e 2025-06-10
FileHash-SHA256 0b3a08a1d90bf52dbf5379c72b8e2b6e76aa1fbf2c2e6c2d32af99c4707598a7 SHA256 of f28d8c5c2283019e6ed788d20240abc8554cadb5 2025-06-10
FileHash-SHA256 1388f124c6af24eefe5483a5a50ab186abdf51a89875036f7383ea51139ab4b4 SHA256 of 37859e94086ec47b3665328e9c9baf665cb869f6 2025-06-10
FileHash-SHA256 3ab29bc71ddd272f33f17c5108c044a570610c06ccba16cde1a4aa67b1524a8b SHA256 of 66bd8db40f4169c7f0fca3d5d15c978efe143cf8 2025-06-10
FileHash-SHA256 42acdf5051bc636dbbb56483fbca925238f1c5422497e2dda73f07b0653e56f2 SHA256 of bb4ffcdbfad40125080c13fa4917a1e836a8d101 2025-06-10
FileHash-SHA256 b85ffc8af90d4312aca9a81e0da00aabe6278fd9c92e933aec7e2da80c2c1f7e SHA256 of 272cf34e8db2078a3170cf0e54255d89785e3c50 2025-06-10
FileHash-SHA256 dcdaa9da5ee4750b1084f7dd99faeed2c713595bb156ac6491b29c2f9e0a1ade SHA256 of 01b99ff47ec6394753f9ccdd2d43b3e804f9ee36 2025-06-10
FileHash-SHA256 ec929123c9a7e9c60868381ba479f7567f0177d09b412e0a1bd4cecc448ba10d SHA256 of 1c757accbc2755e83e530dda11b3f81007325e67 2025-06-10