A sophisticated Iranian cyberespionage group has maintained undetected access to government networks across Iraq and the Kurdistan Regional Government for nearly eight years, representing one of the longest-running advanced persistent threat campaigns in the Middle East.
The group, designated as BladedFeline by security researchers, has been operating since at least 2017, systematically targeting Kurdish diplomatic officials and high-ranking Iraqi government personnel while developing an extensive arsenal of custom malware tools.
BladedFeline’s attack methodology demonstrates exceptional operational security and patience, characteristics typical of state-sponsored threat actors.
The group initially gains access through exploitation of public-facing applications on internet-exposed web servers, subsequently deploying webshells and establishing multiple persistence mechanisms to ensure long-term access.
WeLiveSecurity analysts identified the group in 2023 after discovering their signature Shahmaran backdoor targeting Kurdish diplomatic officials, though evidence suggests their operations began years earlier.
The campaign’s scope extends beyond traditional government targets to include regional telecommunications infrastructure, with researchers documenting successful infiltration of a telecommunications provider in Uzbekistan.
This broad targeting strategy aligns with Iran’s strategic intelligence collection priorities in the region, particularly concerning Western influence in post-invasion Iraq and the Kurdistan region’s diplomatic relationships and oil resources.
.webp)
Security researchers assess with medium confidence that BladedFeline operates as a subgroup within the larger OilRig APT organization, sharing code similarities and tactical patterns with the established Iranian threat actor.
BladedFeline’s impact extends far beyond typical cyberespionage activities, as the group has demonstrated the ability to maintain strategic access to sensitive government communications and decision-making processes.
The prolonged nature of their access suggests successful collection of diplomatic intelligence, policy deliberations, and potentially classified information that could influence regional geopolitical dynamics.
Their sophisticated toolset indicates significant investment in maintaining operational capabilities while avoiding detection by conventional security measures.
Email-Based Command and Control Infrastructure
The group’s most innovative technical achievement lies in their development of the Whisper backdoor, which revolutionizes traditional command and control communications by leveraging compromised Microsoft Exchange email accounts.
.webp)
This approach effectively camouflages malicious traffic within legitimate organizational email flows, making detection extraordinarily difficult for traditional network monitoring systems.
Whisper’s operational workflow demonstrates remarkable technical sophistication. The malware authenticates to compromised webmail accounts using credentials stored in an XML configuration file with base64-encoded elements.
Once authenticated, it establishes email filtering rules with the hardcoded name “MicosoftDefaultRules” that automatically redirect incoming operator commands to specified folders based on subject line criteria containing “PMO”.
The backdoor maintains persistent communication by sending check-in messages every 10 hours to a designated email address, with the subject line “Content” and a message body containing base64-encoded system identification information.
Command execution occurs through encrypted email attachments processed by Whisper’s decryption engine.
The malware uses AES encryption with a 16-byte initialization vector and a hardcoded key to decrypt operator commands, which arrive in the format ;.
Supported operations include file manipulation, PowerShell script execution, and data exfiltration, with all command output encrypted and returned via email attachments to the original sender’s address.
This email-based architecture represents a significant evolution in APT communication methods, effectively exploiting trusted business processes to maintain covert channels while appearing as routine organizational correspondence.
Speed up and enrich threat investigations with Threat Intelligence Lookup! -> 50 trial search requests
