BladedFeline uses sophisticated malicious tools, including backdoors and IIS modules. ESET has established technical ties with the OilRig group, with which it shares code and tactics. The operation confirms the evolution of the group and its cyberespionage objectives in the Middle East
Milan, 10 June 2025 – ESET, a global European leader in the cybersecurity market, has uncovered the latest activities of the Iranian-affiliated cybercriminal group BladedFeline, which has targeted Iraqi and Kurdish government officials as part of a cyberespionage campaign. The group employed a wide range of malicious tools found in compromised systems, a sign of its efforts to maintain and enhance access to the systems of senior officials and government organizations in Iraq and the Kurdish region. The most recent campaign highlights the evolution of BladedFeline's capabilities, which include two tunneling tools (Laret and Pinar), various additional tools and, above all, the custom Whisper backdoor and the malicious Internet Information Services (IIS) module called PrimeCache, both identified and classified by ESET.
Whisper accesses a compromised webmail account on a Microsoft Exchange server and uses it to communicate with attackers via email attachments. PrimeCache also acts as a backdoor: it is a malicious module for IIS that has similarities with the RDAT backdoor, already used by the APT OilRig group.
Based on similarities in the code and other elements of which a further information in the article published on WeLiveSecurity, ESET believes with reasonable certainty that BladedFeline is a subgroup of OilRig, an Iranian-affiliated APT group known for targeting governments and companies in the Middle East. The initial components used in the most recent campaign can be traced back to OilRig. The tools employed reflect the group's strategic orientation towards persistence and stealth within the targeted networks.
BladedFeline continues to operate with the aim of maintaining stable access to the computer systems of Kurdish diplomatic officials. At the same time, it compromised a telecommunications provider in Uzbekistan and continues intrusion activities towards representatives of the Iraqi government.
According to ESET Research, BladedFeline aims to target the Kurdish and Iraqi governments for cyberespionage purposes, with the aim of maintaining strategic access to the computer systems of high-level officials in both administrations. Diplomatic ties between Kurdistan and Western countries, along with the region's oil reserves, make the area a particularly attractive target for Iranian-affiliated groups intent on spying on and potentially manipulating these relationships. In Iraq, these actors are most likely operating to counter Western influence following the US invasion and occupation.
In 2023, ESET had already discovered that BladedFeline had targeted Kurdish diplomatic officials with the Shahmaran backdoor, and reported its activities in the APT Activity Reports. The group has been active since at least 2017, the year in which it compromised officials of the Kurdistan Regional Government. It is not the only subgroup of OilRig monitored by ESET: among others, Lyceum — also known as HEXANE or Storm-0133 — is also under observation. Lyceum focuses on several Israeli targets, including local government bodies and healthcare organizations.
According to ESET, BladedFeline will continue to develop its tools in order to maintain and expand access to environments already infiltrated for cyberespionage purposes.
For an in-depth technical analysis of the tools used by BladedFeline as part of Operation RoundPress, please refer to the ESET Research blog post “Whispering in the dark”, available on WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.






