Also known as: HEXANE, Storm-0133, as another OilRig subgroup, tracked as, APT34
BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The group employs a variety of tools, including the Shahmaran backdoor, Whisper, and PrimeCache, which is a malicious IIS module. BladedFeline utilizes techniques such as spearphishing (T1566), exploiting public-facing applications (T1190), and timestomping to maintain access and exfiltrate data. The group is assessed with medium confidence to be a subgroup of OilRig, focusing on strategic access to high-ranking officials in the region.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BladedFeline is an Iran-aligned Advanced Persistent Threat (APT) group active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The group employs a variety of tools, including the Shahmaran backdoor, Whisper, and PrimeCache, a malicious IIS module, to achieve its objectives.
Goals & Targeting
BladedFeline's strategic objectives appear to center around cyberespionage, targeting Iraqi and Kurdish government officials to obtain sensitive political and military information. The group's targeting profile focuses on sectors relevant to national security, suggesting an intent to gather intelligence that could be used by state actors in the region for strategic advantage.
Enhanced Description
BladedFeline is assessed as an Iran-aligned APT group that has been active since at least 2017. The primary focus of this group appears to be cyberespionage, targeting Iraqi and Kurdish government officials. The group has demonstrated the capability to deploy a range of tools, including the Shahmaran backdoor, Whisper malware, and PrimeCache, which is a malicious IIS module. These tools suggest a level of technical proficiency, enabling the group to compromise systems and exfiltrate sensitive data. BladedFeline's operational methods include spearphishing campaigns (T1566), exploitation of public-facing applications (T1190), and timestomping techniques to maintain persistence and avoid detection. The group is also believed to be a subgroup or affiliate of OilRig, with a specific focus on targeting high-ranking officials in the Middle East for strategic intelligence collection.
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BladedFeline has been observed targeting high-ranking officials in Iraq and Kurdistan through sophisticated cyberespionage campaigns. The group's operational tempo suggests a focus on maintaining persistence within targeted networks to gather sensitive information over extended periods. Notable tools include Shahmaran, which provides backdoor access, and PrimeCache, which exploits memory corruption vulnerabilities in IIS servers for data exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on medium confidence, as while the group has been linked to OilRig and specific tools are known, gaps exist in fully understanding its exact operational capabilities, size, and long-term strategic goals. Additional data would improve confidence.
No campaigns linked yet.
No observed data linked yet.
27
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics