Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BladedFeline

Also known as: HEXANE, Storm-0133, as another OilRig subgroup, tracked as, APT34

Description

BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The group employs a variety of tools, including the Shahmaran backdoor, Whisper, and PrimeCache, which is a malicious IIS module. BladedFeline utilizes techniques such as spearphishing (T1566), exploiting public-facing applications (T1190), and timestomping to maintain access and exfiltrate data. The group is assessed with medium confidence to be a subgroup of OilRig, focusing on strategic access to high-ranking officials in the region.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Defense
Aerospace
Aviation
Energy
Healthcare
Critical infrastructure
Transportation
Financial services
Chemical
Education

Targeted Countries / Regions

IR
IL
IQ
AE
IN
US
TR
LB

AI Analysis

· 1 week ago

Executive Summary

BladedFeline is an Iran-aligned Advanced Persistent Threat (APT) group active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The group employs a variety of tools, including the Shahmaran backdoor, Whisper, and PrimeCache, a malicious IIS module, to achieve its objectives.

Goals & Targeting

BladedFeline's strategic objectives appear to center around cyberespionage, targeting Iraqi and Kurdish government officials to obtain sensitive political and military information. The group's targeting profile focuses on sectors relevant to national security, suggesting an intent to gather intelligence that could be used by state actors in the region for strategic advantage.

Enhanced Description

BladedFeline is assessed as an Iran-aligned APT group that has been active since at least 2017. The primary focus of this group appears to be cyberespionage, targeting Iraqi and Kurdish government officials. The group has demonstrated the capability to deploy a range of tools, including the Shahmaran backdoor, Whisper malware, and PrimeCache, which is a malicious IIS module. These tools suggest a level of technical proficiency, enabling the group to compromise systems and exfiltrate sensitive data. BladedFeline's operational methods include spearphishing campaigns (T1566), exploitation of public-facing applications (T1190), and timestomping techniques to maintain persistence and avoid detection. The group is also believed to be a subgroup or affiliate of OilRig, with a specific focus on targeting high-ranking officials in the Middle East for strategic intelligence collection.

MITRE ATT&CK Tactics

Espionage
Initial Access
Defense Evasion

ATT&CK Techniques

T1566
T1059
T1190

Software / Tooling

Shahmaran backdoor
Whisper
PrimeCache

Campaigns & Victims

BladedFeline has been observed targeting high-ranking officials in Iraq and Kurdistan through sophisticated cyberespionage campaigns. The group's operational tempo suggests a focus on maintaining persistence within targeted networks to gather sensitive information over extended periods. Notable tools include Shahmaran, which provides backdoor access, and PrimeCache, which exploits memory corruption vulnerabilities in IIS servers for data exfiltration.

IOC Patterns

  • Spearphishing emails targeting government officials
  • Malicious IIS module deployment (PrimeCache)
  • Use of timestomping techniques to hide malicious files

Recommended Actions

  • Implement strict access controls on sensitive systems and networks.
  • Monitor network traffic for signs of timestomping or unusual file activity.
  • Conduct regular employee training on phishing emails to mitigate potential spearphishing attempts.

Suggested Tags

APT
cyberespionage
IIS exploit
Middle East
Iraq

Confidence Assessment

The assessment is based on medium confidence, as while the group has been linked to OilRig and specific tools are known, gaps exist in fully understanding its exact operational capabilities, size, and long-term strategic goals. Additional data would improve confidence.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 9 Domain 8 IPv4 Address 1 SHA-1 Hash 2

References

  1. www.welivesecurity.com — Cited by web research for: HEXANE
  2. cloud.google.com — Cited by web research for: MINIBIKE
  3. www.eset.com — Cited by web research for: Custom Backdoor
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl

Intel Summary

27

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
Phishing
Backdoor / C2
Government Targeting
cyberespionage
IIS exploit
Middle East
Iraq

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.