BladedFeline is an Iran-aligned cyberespionage group active since at least 2017, assessed by ESET with medium confidence to be a subgroup of / closely related to OilRig (APT34). It conducts stealthy, long-dwell intelligence operations against Kurdish and Iraqi officials using a custom toolkit of backdoors, reverse tunnels, and malicious IIS/webshell components. Public reporting is essentially single-source (ESET Research).
ESET traces BladedFeline to at least 2017, when it compromised officials within the Kurdistan Regional Government (KRG). The group was rediscovered by ESET in 2023 after operators deployed the Shahmaran backdoor against Kurdish diplomatic officials, and it has since worked to maintain illicit access to those targets while also developing and maintaining access to high-ranking officials in the Government of Iraq (GOI) and exploiting a regional telecommunications provider in Uzbekistan. ESET's June 2025 report 'Whispering in the dark' detailed an evolving arsenal including the Whisper backdoor (which abuses compromised Exchange/webmail accounts for email-based C2), the PrimeCache malicious IIS module (RSA/AES, code-similar to OilRig's RDAT), the Spearal and Veaty backdoors, the Flog ASP.NET webshell, the Laret and Pinar reverse tunnels, the Shahmaran backdoor, and the Python-based Slippery Snakelet. The OilRig/APT34 relationship is drawn from shared tools (VideoSRV, RDAT), code overlap, and common victimology, at medium confidence. Reporting is effectively single-vendor (ESET), so corroboration from independent primary sources is limited. MENA relevance: HIGH and REAL — Iraq, including the Kurdistan Regional Government (KRG), is a confirmed primary, deliberate target of BladedFeline espionage per ESET, with Iran as the origin/sponsor nexus; the campaign is squarely MENA-focused.
+5 more relationships — see the relationships browser.