logo

BladedFeline: Whispering in the dark

ID: a39de837-df3c-578c-93ed-7a6b6abc4a5c

STIX ID: report--a39de837-df3c-578c-93ed-7a6b6abc4a5c

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-06-05

Date Updated: 2026-05-01

...
...

ESET documents BladedFeline, an Iran-aligned APT subgroup active since at least 2017, detailing a multi-year cyberespionage campaign against Kurdish and Iraqi government officials and a regional telecommunications provider; the report provides technical analysis of multiple backdoors and support tools (Whisper, PrimeCache, Shahmaran, Laret/Pinar, Slippery Snakelet, etc.), a timeline, IoCs (hashes, IPs, domains), and mappings to MITRE ATT&CK techniques, and assesses BladedFeline with medium confidence as a subgroup of OilRig.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.