BladedFeline is an Iran-aligned threat actor known for cyberespionage targeting government officials.
Analyst brief
BladedFeline is an Iran-aligned threat actor active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. They utilize TTPs like spearphishing, exploitation of public-facing applications, and timestomping, along with tools such as the Shahmaran backdoor, Whisper, and the PrimeCache malicious IIS module. Defenders should focus on email security, web server log analysis, and detecting anomalies within IIS environments.
BladedFeline
unknown
BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The group employs a variety of tools, including the Shahmaran backdoor, Whisper, and PrimeCache, which is a malicious IIS module. BladedFeline utilizes techniques such as spearphishing (T1566), exploiting public-facing applications (T1190), and timestomping to maintain access and exfiltrate data. The group is assessed with medium confidence to be a subgroup of OilRig, focusing on strategic access to high-ranking officials in the region.