Iranian Cyberespionage Targets Iraqi Government Officials
ID: 64d9dbc7-c11b-50bb-9c98-2a0eb013c280
STIX ID: report--64d9dbc7-c11b-50bb-9c98-2a0eb013c280
Feed Name: ThreatCluster
In 2024 the Iranian APT group BladedFeline executed an active cyberespionage campaign against Kurdish and Iraqi government officials, deploying advanced backdoors (Shahmaran, Whisper), abusing compromised email accounts for command-and-control, and using unique C2 channels including DNS tunneling and email-based mechanisms; ESET associates BladedFeline with the OilRig APT, and Check Point observed double-extension files used for initial compromise, indicating sustained, sophisticated nation-state activity that requires continued monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
