Advanced threat actors have been infiltrating Middle Eastern government networks using innovative email-based malware and malicious web server modules for years, new research reveals.
Cybersecurity researchers at ESET have uncovered a sophisticated cyberespionage campaign conducted by BladedFeline, an Iranian-aligned advanced persistent threat (APT) group that has been systematically targeting Kurdish and Iraqi government officials since at least 2017.
The group has deployed two particularly notable tools: Whisper, a backdoor that exploits Microsoft Exchange servers through email communications, and PrimeCache, a malicious Internet Information Services (IIS) module.
BladedFeline first came to researchers’ attention in 2023 when they deployed the Shahmaran backdoor against Kurdish diplomatic officials.
However, analysis of compromised systems revealed the group had been operating since 2017, initially targeting officials within the Kurdistan Regional Government (KRG).
The group’s name derives from their consistent focus on regional government entities and their connection to Iranian state interests.
ESET researchers assess with medium confidence that BladedFeline operates as a subgroup of OilRig, a well-known Iranian APT group also known as APT34 or Hazel Sandstorm.
This assessment is based on code similarities between BladedFeline’s tools and known OilRig malware, particularly the RDAT backdoor, as well as overlapping targeting patterns and technical infrastructure.
Whisper: Email-Based Backdoor
The Whisper backdoor represents a novel approach to command and control communications.
Rather than using traditional network protocols, Whisper operates by logging into compromised Microsoft Exchange webmail accounts and communicating with attackers through email attachments.

The malware creates inbox rules to automatically process commands received via email, then executes them and returns results through encrypted email attachments.
Whisper’s operational workflow involves seven distinct steps: gaining access to compromised email accounts, establishing inbox rules for command processing, sending periodic check-in messages, fetching encrypted operator commands from email attachments, decrypting and executing these commands, and finally returning results via encrypted email responses.
The backdoor can execute PowerShell scripts, transfer files, and perform system reconnaissance.
PrimeCache: Malicious IIS Module
PrimeCache functions as a passive backdoor implemented as a native IIS module, allowing attackers to maintain persistent access to compromised web servers.
The malware filters incoming HTTP requests, only processing those containing specific cookie headers that identify communications from BladedFeline operators.
Unlike traditional backdoors that process commands in single requests, PrimeCache uses a unique multi-request approach.

Operators first send individual requests for each parameter, which are stored in memory, then trigger the actual command execution with a separate request. This method helps evade detection by breaking up malicious traffic patterns.
The backdoor supports various functions, including remote command execution, file upload and download capabilities, and system reconnaissance.
It uses RSA and AES encryption for secure communications, with operators transmitting commands through cookie headers and receiving responses in HTTP response bodies.
Campaign Timeline and Victims
The campaign timeline spans from 2017 to 2024, showing the continuous evolution of BladedFeline’s toolset.
Starting with basic reverse shells and progressing to sophisticated backdoors, the group has maintained persistent access to victim networks across multiple countries, including Iraq, Kurdistan, and Uzbekistan.
Victims include high-ranking officials within the Kurdistan Regional Government, Iraqi government entities, and a regional telecommunications provider in Uzbekistan.
The group’s focus on diplomatic and government targets suggests intelligence gathering motivations aligned with Iranian strategic interests.
This campaign demonstrates the continued sophistication of Iranian state-sponsored cyber operations targeting Middle Eastern governments.
The innovative use of legitimate Microsoft Exchange infrastructure for command and control represents a concerning evolution in APT tactics, potentially making detection and attribution more challenging for defenders.
Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now
