logo

Iranian Cyberespionage Targets Iraqi Government Officials

ID: 64d9dbc7-c11b-50bb-9c98-2a0eb013c280

STIX ID: report--64d9dbc7-c11b-50bb-9c98-2a0eb013c280

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

...
...

In 2024 the Iranian APT group BladedFeline executed an active cyberespionage campaign against Kurdish and Iraqi government officials, deploying advanced backdoors (Shahmaran, Whisper), abusing compromised email accounts for command-and-control, and using unique C2 channels including DNS tunneling and email-based mechanisms; ESET associates BladedFeline with the OilRig APT, and Check Point observed double-extension files used for initial compromise, indicating sustained, sophisticated nation-state activity that requires continued monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.