×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Information Tecnology
  • BladedFeline, Iran-affiliated group, targets Iraqi and Kurdish officials: ESET Research finds

Customer Press Room

BladedFeline, Iran-affiliated group, targets Iraqi and Kurdish officials: ESET Research finds

by Grandangolo Communications / Tuesday, 10 June 2025 / Published in Information Tecnology

BladedFeline uses sophisticated malicious tools, including backdoors and IIS modules. ESET has established technical ties with the OilRig group, with which it shares code and tactics. The operation confirms the evolution of the group and its cyberespionage objectives in the Middle East

Milan, 10 June 2025 – ESET, a global European leader in the cybersecurity market, has uncovered the latest activities of the Iranian-affiliated cybercriminal group BladedFeline, which has targeted Iraqi and Kurdish government officials as part of a cyberespionage campaign. The group employed a wide range of malicious tools found in compromised systems, a sign of its efforts to maintain and enhance access to the systems of senior officials and government organizations in Iraq and the Kurdish region. The most recent campaign highlights the evolution of BladedFeline's capabilities, which include two tunneling tools (Laret and Pinar), various additional tools and, above all, the custom Whisper backdoor and the malicious Internet Information Services (IIS) module called PrimeCache, both identified and classified by ESET.

Whisper accesses a compromised webmail account on a Microsoft Exchange server and uses it to communicate with attackers via email attachments. PrimeCache also acts as a backdoor: it is a malicious module for IIS that has similarities with the RDAT backdoor, already used by the APT OilRig group.

Based on similarities in the code and other elements of which a further information in the article published on WeLiveSecurity, ESET believes with reasonable certainty that BladedFeline is a subgroup of OilRig, an Iranian-affiliated APT group known for targeting governments and companies in the Middle East. The initial components used in the most recent campaign can be traced back to OilRig. The tools employed reflect the group's strategic orientation towards persistence and stealth within the targeted networks.

BladedFeline continues to operate with the aim of maintaining stable access to the computer systems of Kurdish diplomatic officials. At the same time, it compromised a telecommunications provider in Uzbekistan and continues intrusion activities towards representatives of the Iraqi government.

According to ESET Research, BladedFeline aims to target the Kurdish and Iraqi governments for cyberespionage purposes, with the aim of maintaining strategic access to the computer systems of high-level officials in both administrations. Diplomatic ties between Kurdistan and Western countries, along with the region's oil reserves, make the area a particularly attractive target for Iranian-affiliated groups intent on spying on and potentially manipulating these relationships. In Iraq, these actors are most likely operating to counter Western influence following the US invasion and occupation.

In 2023, ESET had already discovered that BladedFeline had targeted Kurdish diplomatic officials with the Shahmaran backdoor, and reported its activities in the APT Activity Reports. The group has been active since at least 2017, the year in which it compromised officials of the Kurdistan Regional Government. It is not the only subgroup of OilRig monitored by ESET: among others, Lyceum — also known as HEXANE or Storm-0133 — is also under observation. Lyceum focuses on several Israeli targets, including local government bodies and healthcare organizations.

According to ESET, BladedFeline will continue to develop its tools in order to maintain and expand access to environments already infiltrated for cyberespionage purposes.

For an in-depth technical analysis of the tools used by BladedFeline as part of Operation RoundPress, please refer to the ESET Research blog post “Whispering in the dark”, available on WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.

About Grandangolo Communications

What you can read next

Cohesity Launches FortKnox - Countering Ransomware with a SaaS Data Isolation and Recovery Solution
According to the new HYCU® report, over 60% of attacks successfully conducted via SaaS applications are of ransomware origin
Cohesity Announces DataHawk: Protection, Detection and Recovery from Cyber ​​Attacks, All in One SaaS Security Offering

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP