PULSE NAME
Whispering in the dark
WHITE BladedFeline AlienVault 2025-06-10 Modified: 2025-07-10
33
IOCs
MEDIUM VOLUME
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan.
Indicators of Compromise (2 / 33 total)
All FileHash-MD5 URL FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
URL http://178.209.51.61:8000/wincapsrv.exe 2025-06-10
URL https://zaincell.store/request/ 2025-06-10