BladedFeline: Whispering in the dark
Essential information
- Published
- 06/06/2025 11:02
- Modified
- 08/06/2025 16:53
- Tags
- 2025-06-06 apt backdoor iis malware oilrig shahmaran slippery snakelet whisper
- Related entities
- 3 observables, 1 intrusion sets (apt), 17 techniques (mitre), 3 others
Description
ESET researchers have uncovered a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has been targeting Kurdish and Iraqi government officials since at least 2017, using various malicious tools including reverse tunnels, backdoors, and a malicious IIS module. Key malware includes the Whisper backdoor, which communicates via compromised email accounts, and PrimeCache, a malicious IIS module with similarities to OilRig's RDAT backdoor. The campaign also targeted a telecommunications provider in Uzbekistan. BladedFeline's sophisticated tactics and tools indicate a focus on maintaining strategic access to high-ranking officials for espionage purposes.