Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1071.004 ↗inferred | Application Layer Protocol: DNS | Command and Control | Spearal backdoor tunnels C2 in DNS query subdomains using custom Base32 encoding to iqwebservice[.]com (Check Point 2024) |
| T1071.003 ↗inferred | Application Layer Protocol: Mail Protocols | Command and Control | Whisper/Veaty poll compromised Exchange mailboxes every ~10h for AES-encrypted email attachments carrying commands; Exchange inbox rules (subject marker 'PMO') filter tasking (ESET 2025, Check Point 2024) |
| T1572 ↗inferred | Protocol Tunneling | Command and Control | Laret and Pinar .NET reverse SSH tunnels with port forwarding (local port 9666) bridge network segments (ESET 2025) |
| T1003.001 ↗inferred | OS Credential Dumping: LSASS Memory | Credential Access | ESET observed LSASS memory dumping on KRG systems on 2023-01-23 (ESET 2025 ATT&CK table) |
| T1070.006 ↗inferred | Indicator Removal: Timestomp | Defense Evasion | PowerShell-based timestomping used to obscure implant installation dates (Check Point 2024; ESET 2025 maps T1070.006) |
+5 more relationships — see the relationships browser.
| T1059.001 ↗inferred | Command and Scripting Interpreter: PowerShell | Execution | Whisper executes PowerShell scripts as a command; P.S. Olala service runs TrainedDataStore.ps1; PowerShell droppers for Spearal (ESET 2025) |
| T1204.002 ↗inferred | User Execution: Malicious File | Execution | Double-extension lures Protocol.pdf.exe / Avamer.pdf.exe and an MSI installer carrying the Iraqi General Secretariat logo dropped Whisper/Spearal (Check Point 2024, ESET 2025) |
| T1048.001 ↗inferred | Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Exfiltration | Whisper exfiltrates files as AES-encrypted email attachments via the compromised Exchange account (ESET 2025 ATT&CK table) |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | ESET maps initial access to exploitation of internet-facing servers; Flog webshell (flogon.aspx) and PrimeCache IIS module deployed on compromised web servers |
| T1543.003 ↗inferred | Create or Modify System Process: Windows Service | Persistence | Pinar reverse tunnel and P.S. Olala PowerShell executor register themselves as Windows services (ESET 2025) |
| T1547.001 ↗inferred | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Persistence | Whisper dropper creates VeeamUpdate.lnk in Startup folder; Run key entry 'Forti Startup' observed (ESET 2025, Check Point 2024) |
| T1505.004 ↗inferred | Server Software Component: IIS Components | Persistence | PrimeCache/CacheHttp.dll malicious native IIS HttpModule acting as passive backdoor, commands delivered via Cookie header F=<id>,<param> (ESET 2025, Check Point 2024) |
| T1505.003 ↗inferred | Server Software Component: Web Shell | Persistence | Flog ASP.NET webshell (flogon.aspx, MD5-password protected) providing directory listing and file create/delete on compromised servers (ESET 2025) |
| T1586.002 ↗inferred | Compromise Accounts: Email Accounts | Resource Development | Whisper and Veaty backdoors operate through compromised Exchange webmail accounts inside KRG/GOI victim networks (ESET 2025, Check Point 2024) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside BladedFeline's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter BladedFeline's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.