{"id":3325,"date":"2025-06-08T13:24:30","date_gmt":"2025-06-08T13:24:30","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=3325"},"modified":"2025-06-08T13:24:31","modified_gmt":"2025-06-08T13:24:31","slug":"bladedfeline-whispering-in-the-dead-of-night","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=3325","title":{"rendered":"BladedFeline: Whispering in the dead of night"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>In 2024, ESET researchers found a number of malicious instruments within the methods utilized by Kurdish and Iraqi authorities officers. The APT group behind the assaults is BladedFeline, an Iranian risk actor that has been lively since a minimum of 2017, when it compromised officers inside the Kurdistan Regional Authorities (KRG). This group develops malware for sustaining and increasing entry inside organizations in Iraq and the KRG. Whereas that is our first blogpost overlaying BladedFeline, we found the group in 2023, after it focused Kurdish diplomatic officers with the Shahmaran backdoor, and beforehand reported on its actions in ESET APT Exercise experiences <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-apt-activity-report-q4-2023-q1-2024.pdf\" target=\"_blank\" rel=\"noopener\">This autumn 2023-Q1 2024<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-apt-activity-report-q2-2024-q3-2024.pdf\" target=\"_blank\" rel=\"noopener\">Q2 2024-Q3 2024<\/a>.<\/p>\n<p>The array of instruments utilized within the latest marketing campaign exhibits that since deploying Shahmaran, BladedFeline has continued to develop its arsenal. We discovered two reverse tunnels, quite a lot of supplementary instruments, and most notably, a backdoor that we named Whisper and a malicious IIS module we dubbed PrimeCache. Whisper is a backdoor that logs right into a compromised webmail account on a Microsoft Change server and makes use of it to speak with the attackers through e mail attachments. PrimeCache additionally serves as a backdoor: it&#8217;s a malicious IIS module associated to what we known as Group 2 in our 2021 paper <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2021\/08\/06\/anatomy-native-iis-malware\/\" target=\"_blank\" rel=\"noopener\">Anatomy of native IIS malware<\/a>. Considerably, PrimeCache additionally bears similarities to the RDAT backdoor utilized by the Iran-aligned OilRig APT group.<\/p>\n<p>Based mostly on these code similarities, in addition to on additional proof introduced on this blogpost, we assess with medium confidence that BladedFeline is a subgroup of OilRig, an Iran-aligned APT group going after governments and companies within the Center East. We now have beforehand <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes\/\" target=\"_blank\" rel=\"noopener\">reported<\/a> on different <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/oilrig-persistent-attacks-cloud-service-powered-downloaders\/\" target=\"_blank\" rel=\"noopener\">exercise<\/a> linked to OilRig. To keep away from confusion, we&#8217;ve got since refined our OilRig monitoring, and we now monitor each of these operations underneath a separate subgroup \u2013 Lyceum \u2013 inside OilRig.<\/p>\n<p>BladedFeline has labored persistently to keep up illicit entry to Kurdish diplomatic officers, whereas concurrently exploiting a regional telecommunications supplier in Uzbekistan, and creating and sustaining entry to officers within the authorities of Iraq. This blogpost particulars the technical points of the preliminary implants delivered to BladedFeline\u2019s targets, the hyperlinks between the victims, and lays the groundwork for associating this subgroup with OilRig.<\/p>\n<blockquote>\n<p><strong>Key factors of the blogpost:<\/strong><\/p>\n<ul>\n<li>BladedFeline compromised officers inside the Kurdistan Regional Authorities a minimum of as early as 2017.<\/li>\n<li>The preliminary implants used there will be traced again to OilRig.<\/li>\n<li>We found BladedFeline after its operators compromised Kurdish diplomatic officers with the group\u2019s Shahmaran signature backdoor in 2023.<\/li>\n<li>This APT group has additionally infiltrated high-ranking officers inside the authorities of Iraq.<\/li>\n<li>We assess with medium confidence that BladedFeline is a subgroup inside OilRig.<\/li>\n<li>We analyze two reverse tunnels (Laret and Pinar), a backdoor (Whisper), a malicious IIS module (PrimeCache), and varied supplementary instruments.<\/li>\n<\/ul>\n<\/blockquote>\n<h2>BladedFeline overview<\/h2>\n<p>BladedFeline is an Iran-aligned cyberespionage group, lively since a minimum of 2017 in line with ESET telemetry. We found the group in 2023 when it deployed its Shahmaran backdoor towards Kurdish diplomatic officers. Shahmaran, named after a legendary half-snake, half-woman creature from Iranian folklore, is a 64-bit moveable executable that we discovered within the goal\u2019s Startup listing. This easy backdoor doesn\u2019t use any compression or encryption for community communications. After checking in with the C&amp;C server, the backdoor executes any operator instructions offered, which embody importing and downloading further information, requesting particular file attributes and offering file and listing manipulation API.<\/p>\n<p>As evidenced by the marketing campaign toolset we describe on this blogpost; since deploying Shahmaran, BladedFeline has continued to develop its malware as a way to retain and even additional lengthen its entry to the KRG and to excessive ranges inside the authorities of Iraq (GOI). We uncovered the marketing campaign in 2024 after discovering BladedFeline\u2019s Whisper backdoor, PrimeCache IIS backdoor, and a set of post-compromise instruments within the networks of Kurdish diplomatic officers, Iraqi authorities officers, and a regional telecommunications supplier in Uzbekistan.<\/p>\n<p>We detected and picked up one model of Whisper and located one other on VirusTotal, uploaded by a person in Iraq. They&#8217;re nearly equivalent, and we had been in a position to decide the possible identification of the VirusTotal uploader, primarily based on knowledge within the Whisper pattern and different samples uploaded underneath the identical submitter ID. PrimeCache, Flog (a webshell), and Hawking Listener (an early-stage implant that listens on a specified port) had been all uploaded to VirusTotal by the identical submitter ID who uploaded the Whisper samples. Based mostly on the Whisper hyperlink and the shut timeframe (each had been uploaded inside a matter of minutes) we consider it was deployed by BladedFeline to a sufferer in Iraq\u2019s authorities. Among the instruments talked about under within the <em>Timeline<\/em> are mentioned later within the report (e.g., Slippery Snakelet).<\/p>\n<h3>Timeline<\/h3>\n<pre>2017-09-21 \u25cf VideoSRV reverse shell on KRG system\n           |\n2018-01-30 \u25cf RDAT backdoor on KRG system\n           |\n2019-07-09 \u25cf Customized Plink on KRG system\n           |\n2021-05-01 \u25cf Sheep Tunneler on KRG system\n           |\n2023-01-23 \u25cf LSASS dumped on KRG system\n           |\n2023-02-01 \u25cf Shahmaran backdoor on KRG system\n           |\n2023-03-25 \u25cf First sufferer focused at a telecommunications firm in Uzbekistan\n           |\n2023-06-12 \u25cf Shahmaran model 2 on KRG system for entry upkeep\n           |\n2023-12-14 \u25cf BladedFeline operators executing CLI instructions on KRG system\n           |\n2023-12-16 \u25cf Slippery Snakelet backdoor on KRG system\n           |\n2023-12-20 \u25cf P.S. Olala (a PowerShell executor) on KRG system\n           |\n2023-12-20 \u25cf PsExec on KRG system\n           |\n2024-01-07 \u25cf Whisper backdoor on KRG system\n           |\n2024-02-01 \u25cf Laret reverse tunnel on KRG system\n           |\n2024-02-20 \u25cf Pinar reverse tunnel on KRG system\n           |\n2024-02-29 \u25cf PrimeCache malicious IIS module uploaded to VirusTotal\n           |\n2024-03-11 \u25cf Whisper model 2, Flog, and Hawking Listener uploaded to VirusTotal<\/pre>\n<h3>Attribution<\/h3>\n<p>Our attribution of this marketing campaign to BladedFeline is predicated on the next:<\/p>\n<ul>\n<li>The marketing campaign targets members of the KRG, as have earlier assaults carried out by BladedFeline.<\/li>\n<li>The unique assault exercise focusing on the KRG group allowed us to determine successive malware, as BladedFeline has tried to keep up and broaden entry to the group.<\/li>\n<li>Additional evaluation of the assaults led us to determine the telecommunications sufferer in Uzbekistan.<\/li>\n<li>On the identical time, wanting into the Whisper backdoor helped us determine the GOI sufferer.<\/li>\n<\/ul>\n<p>We assess that BladedFeline is focusing on the KRG and the GOI for cyberespionage functions, with a watch towards sustaining strategic entry to high-ranking officers in each governmental entities. The KRG\u2019s diplomatic relationship with Western nations, coupled with the oil reserves within the Kurdistan area, makes it an attractive goal for Iran-aligned risk actors to spy on and probably manipulate. In Iraq, these risk actors are most likely making an attempt to counter the affect of Western governments following the US invasion and occupation of the nation.<\/p>\n<p>We consider with medium confidence that BladedFeline is a subgroup of OilRig:<\/p>\n<ul>\n<li>As does OilRig, BladedFeline targets organizations within the Center East with the aim of cyberespionage.<\/li>\n<li>We now have discovered OilRig instruments (VideoSRV and RDAT) in a compromised KRG system.<\/li>\n<li>BladedFeline\u2019s malicious IIS module PrimeCache shares code similarities with OilRig\u2019s RDAT.<\/li>\n<\/ul>\n<p>BladedFeline shouldn&#8217;t be the one subgroup of OilRig that we&#8217;re monitoring: we&#8217;ve got already been monitoring Lyceum, also referred to as HEXANE or Storm-0133, as one other OilRig subgroup. Lyceum focuses on focusing on varied Israeli organizations, together with governmental and native governmental entities and organizations in healthcare. Main instruments we attribute to Lyceum embody <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/vblocalhost.com\/uploads\/VB2021-Kayal-etal.pdf\" target=\"_blank\" rel=\"noopener\">DanBot<\/a>, the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20230129145433\/https:\/www.prevailion.com\/latest-targets-of-cyber-group-lyceum\/\" target=\"_blank\" rel=\"noopener\">Shark, Milan<\/a>, and Marlin backdoors, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes\/\" target=\"_blank\" rel=\"noopener\">Photo voltaic and Mango<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-apt-activity-report-q2-2023-q3-2023.pdf\" target=\"_blank\" rel=\"noopener\">OilForceGTX<\/a>, and a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/oilrig-persistent-attacks-cloud-service-powered-downloaders\/\" target=\"_blank\" rel=\"noopener\">number of downloaders<\/a> utilizing professional cloud companies for C&amp;C communication.<\/p>\n<p>We&#8217;ll proceed to make use of the identify OilRig to check with the mother or father group, also referred to as APT34 or Hazel Sandstorm (previously EUROPIUM). OilRig is a cyberespionage group that has been lively since a minimum of 2014 and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/groups\/G0049\/\" target=\"_blank\" rel=\"noopener\">is often believed<\/a> to be primarily based in Iran. The group targets Center Japanese governments and quite a lot of enterprise verticals, together with chemical, vitality, finance, and telecommunications. Notable OilRig campaigns embody the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.talosintelligence.com\/2018\/11\/dnspionage-campaign-targets-middle-east.html\" target=\"_blank\" rel=\"noopener\">2018<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.talosintelligence.com\/2019\/04\/dnspionage-brings-out-karkoff.html\" target=\"_blank\" rel=\"noopener\">2019<\/a> DNSpionage marketing campaign, focusing on victims in Lebanon and the United Arab Emirates; the 2019\u20132020 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.mandiant.com\/resources\/hard-pass-declining-apt34-invite-to-join-their-professional-network\" target=\"_blank\" rel=\"noopener\">HardPass<\/a> marketing campaign, utilizing LinkedIn to focus on Center Japanese victims within the vitality and authorities sectors; <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/oilrig-novel-c2-channel-steganography\/\" target=\"_blank\" rel=\"noopener\">the 2020 assault<\/a> towards a telecommunications group within the Center East utilizing the RDAT backdoor; and the 2023 assaults focusing on organizations within the Center East with the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/crambus-middle-east-government\" target=\"_blank\" rel=\"noopener\">PowerExchange<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/b\/new-apt34-malware-targets-the-middle-east.html\" target=\"_blank\" rel=\"noopener\">MrPerfectionManager<\/a> backdoors.<\/p>\n<h4>OilRig instruments utilized by BladedFeline<\/h4>\n<p>We now have discovered two OilRig instruments on the KRG machines compromised by BladedFeline.<\/p>\n<h5>RDAT<a rel=\"nofollow\" target=\"_blank\" id=\"RDAT\"\/><\/h5>\n<p>We found a beforehand unreported model of the OilRig backdoor RDAT on two KRG sufferer methods. Analyzing RDAT, we discovered that the operational circulation (see <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/oilrig-novel-c2-channel-steganography\/\" target=\"_blank\" rel=\"noopener\">Unit 42\u2019s report<\/a> for specifics), compilation timestamp (2017-12-26 10:49:35), and file write time (2018-01-30) align with OilRig exercise and focusing on, significantly with regard to the group\u2019s 2017 exercise. We noticed a file with an SHA-1 of <span style=\"font-family: courier new, courier, monospace;\">562E1678EC8FDC1D83A3F73EB511A6DDA08F3B3D<\/span> and a path of <span style=\"font-family: courier new, courier, monospace;\">C:WindowsSystem32LogonUl.exe<\/span> on each methods. The PDB path additionally corroborates that this binary is RDAT: <span style=\"font-family: courier new, courier, monospace;\">C:UsersVoidDesktopRDATclientx64Releaseclient.pdb<\/span>. To this point, we&#8217;ve got solely ever noticed RDAT in use by OilRig. Furthermore, we&#8217;ve got not seen any customized implant sharing between OilRig and different Center Japanese teams, and it seldom happens between Iran-aligned risk actors.<\/p>\n<p>Additional bolstering the case that BladedFeline is an OilRig subgroup, as with Lyceum, is the evaluation linking RDAT with PrimeCache, a malicious IIS module that was uploaded to VirusTotal presumably by the GOI sufferer. This hyperlink is explored in additional depth within the <em><a rel=\"nofollow\" target=\"_blank\" href=\"#Links with OilRig\">Hyperlinks with OilRig<\/a><\/em> part of the blogpost.<\/p>\n<h5>VideoSRV<\/h5>\n<p>One further knowledge level on the OilRig and BladedFeline connection is a reverse shell deployed to one of many KRG victims (September 21<sup>st<\/sup>, 2017) previous to RDAT getting dropped on the identical system (January 30<sup>th<\/sup>, 2018). VideoSRV (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">BE0AD25B7B48347984908175404996531CFD74B7<\/span>), so named for its filename videosrv.exe, has the PDB string <span style=\"font-family: courier new, courier, monospace;\">C:Usersv0idDesktopreverseShellclientProxyx64ReleaseConsoleApplication1.pdb<\/span>, which bears some similarities to the RDAT PDB string <span style=\"font-family: courier new, courier, monospace;\">C:UsersVoidDesktopRDATclientx64Releaseclient.pdb<\/span>.<\/p>\n<h2>Technical evaluation<\/h2>\n<h3>Preliminary entry<\/h3>\n<p>It&#8217;s nonetheless unclear how BladedFeline is creating entry to its victims. What we all know is that within the case of the KRG victims, the risk actors obtained entry a minimum of way back to 2017 and have maintained it ever since. As for the GOI victims, we suspect that the group exploited a vulnerability in an software on an internet-facing net server, which allowed them to deploy the Flog webshell.<\/p>\n<h3>Toolset<\/h3>\n<h4>PrimeCache \u2013 malicious IIS module<\/h4>\n<p>PrimeCache, whose identify we derived from the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/cpp\/cpp\/run-time-type-information?view=msvc-170\" target=\"_blank\" rel=\"noopener\">RTTI<\/a> <span style=\"font-family: courier new, courier, monospace;\">AVRSAPrimeSelector<\/span> and its filename (<span style=\"font-family: courier new, courier, monospace;\">cachehttp.dll<\/span>), is a passive backdoor carried out as a local IIS module with an inside identify of <span style=\"font-family: courier new, courier, monospace;\">HttpModule.dll<\/span>. It was uploaded to VirusTotal by the identical person who uploaded one of many Whisper backdoor samples. It&#8217;s a 64-bit C++ DLL with a compilation timestamp of 2023-05-14 06:55:52 and has a minimized PDB string of simply <span style=\"font-family: courier new, courier, monospace;\">HttpModule.pdb<\/span>. It has a single export: <span style=\"font-family: courier new, courier, monospace;\">RegisterModule<\/span>.<\/p>\n<p>PrimeCache is a successor to a group of unattributed IIS backdoors that we&#8217;ve got beforehand reported as Group 2 (easy IIS backdoors) in our 2021 blogpost, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2021\/08\/06\/anatomy-native-iis-malware\/\" target=\"_blank\" rel=\"noopener\">Anatomy of native IIS malware<\/a>. We obtained these unique samples from VirusTotal the place they had been uploaded by customers from Bahrain, Israel, and Pakistan, between 2018 and 2020. Based mostly solely on the situation of the presumed victims, it&#8217;s potential that these instances had been additionally associated to BladedFeline \u2013 or, extra broadly, OilRig \u2013 actions.<\/p>\n<h5>Foremost performance<\/h5>\n<p>PrimeCache\u2019s important performance is carried out within the <span style=\"font-family: courier new, courier, monospace;\">CGlobalModule::OnGlobalPreBeginRequest<\/span> handler. This can be a distinctive implementation, differing from its predecessors, which used the <span style=\"font-family: courier new, courier, monospace;\">CHttpModule::OnBeginRequest<\/span> handler. PrimeCache filters incoming HTTP requests, solely processing these from the BladedFeline operators, that are acknowledged by having a <span style=\"font-family: courier new, courier, monospace;\">cookie<\/span> header with the construction:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">F=<command_id>,<param\/>;<\/command_id><\/span><\/p>\n<p>Notice that this worth will be standalone or embedded into an extended cookie, surrounded by semicolon (<span style=\"font-family: courier new, courier, monospace;\">;<\/span>) characters.<\/p>\n<p>The backdoor works in an uncommon method (new with this model as in contrast with our 2021 evaluation). Relatively than accepting a backdoor command and all its parameters inside a single HTTP request, every motion is break up into a number of requests. First, the BladedFeline operator sends a person request for every single parameter; these parameters are saved in a worldwide construction. Then the operator sends one other request to set off the backdoor command. Lastly, PrimeCache makes use of the beforehand acquired parameters to execute the desired motion, after which clears the cached parameters.<\/p>\n<h5>Operator instructions<\/h5>\n<p>There are three sorts of requests that may be acquired by the backdoor, as proven in Desk 1.<\/p>\n<p style=\"text-align: center;\"><em>Desk 1. PrimeCache operator instructions<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"123\"><strong><span style=\"font-family: courier new, courier, monospace;\"><command_id\/><\/span><\/strong><\/td>\n<td width=\"229\"><strong>Parameter<\/strong><\/td>\n<td width=\"291\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">1<\/span><\/td>\n<td width=\"229\">Format: <span style=\"font-family: courier new, courier, monospace;\"><key>=<value\/><\/key><\/span><\/td>\n<td width=\"291\">Clears the checklist of beforehand saved parameters and provides the brand new worth. Most parameters are encrypted; see <em><a rel=\"nofollow\" target=\"_blank\" href=\"#Encryption\">Encryption<\/a><\/em> under.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">0<\/span><\/td>\n<td width=\"229\">Not used.<\/td>\n<td width=\"291\">Triggers the backdoor motion, utilizing beforehand transmitted backdoor parameters.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">Different<\/span><\/td>\n<td width=\"229\">Format: <span style=\"font-family: courier new, courier, monospace;\"><key>=<value\/><\/key><\/span><\/td>\n<td width=\"291\">Provides the desired worth to the checklist of saved parameters (doesn\u2019t clear the checklist). Most parameters are encrypted; see <em><a rel=\"nofollow\" target=\"_blank\" href=\"#Encryption\">Encryption<\/a><\/em> under.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>As soon as the motion is triggered (through <span style=\"font-family: courier new, courier, monospace;\"><command_id>=0<\/command_id><\/span>), PrimeCache performs an motion, primarily based on the beforehand obtained parameters, as proven in Desk 2. One observe on the chart under:<\/p>\n<p>The PrimeCache motion is operator command (OpCom) <span style=\"font-family: courier new, courier, monospace;\">a<\/span>, the session secret&#8217;s OpCom <span style=\"font-family: courier new, courier, monospace;\">okay<\/span>, binary knowledge is OpCom <span style=\"font-family: courier new, courier, monospace;\">b<\/span>, and the filename is OpCom <span style=\"font-family: courier new, courier, monospace;\">f<\/span>.<\/p>\n<p style=\"text-align: center;\"><em>Desk 2. PrimeCache post-operator command actions<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"94\"><strong>PrimeCache motion<\/strong><\/td>\n<td width=\"104\"><strong>Session key<\/strong><\/td>\n<td width=\"104\"><strong>Binary knowledge<\/strong><\/td>\n<td width=\"85\"><strong>Filename<\/strong><\/td>\n<td width=\"184\"><strong>Command description<\/strong><\/td>\n<td width=\"71\"><strong>Return worth<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"94\"><span style=\"font-family: courier new, courier, monospace;\">r<\/span><\/td>\n<td rowspan=\"5\" width=\"104\">RSA-encrypted session key<\/td>\n<td rowspan=\"3\" width=\"104\">AES-encrypted command line<\/td>\n<td rowspan=\"3\" width=\"85\">Null<\/td>\n<td width=\"184\">Runs the desired command through <span style=\"font-family: courier new, courier, monospace;\">popen<\/span>.<\/td>\n<td rowspan=\"3\" width=\"71\">Command output<\/td>\n<\/tr>\n<tr>\n<td width=\"94\"><span style=\"font-family: courier new, courier, monospace;\">r2<\/span><\/td>\n<td width=\"184\">Runs the desired command through <span style=\"font-family: courier new, courier, monospace;\">CreateProcessW<\/span>.<\/td>\n<\/tr>\n<tr>\n<td width=\"94\"><span style=\"font-family: courier new, courier, monospace;\">r3<\/span><\/td>\n<td width=\"184\">(Presumably) runs the desired command by sending it to a different (unknown) course of through the named pipe <span style=\"font-family: courier new, courier, monospace;\">.pipeiis<\/span>, then reads (presumably) the command output from the identical pipe.<\/td>\n<\/tr>\n<tr>\n<td width=\"94\"><span style=\"font-family: courier new, courier, monospace;\">u<\/span><\/td>\n<td width=\"104\">AES-encrypted file content material<\/td>\n<td rowspan=\"2\" width=\"85\">Native filename<\/td>\n<td width=\"184\">Creates an area file with the desired identify and content material.<\/td>\n<td width=\"71\"><span style=\"font-family: courier new, courier, monospace;\">OK<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"94\"><span style=\"font-family: courier new, courier, monospace;\">d<\/span><\/td>\n<td width=\"104\">Null<\/td>\n<td width=\"184\">Exfiltrates the given file from the compromised IIS server.<\/td>\n<td width=\"71\">File content material<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h5>Encryption<a rel=\"nofollow\" target=\"_blank\" id=\"Encryption\"\/><\/h5>\n<p>Much like its predecessors, PrimeCache makes use of each RSA and AES-CBC for its C&amp;C communication. The parameters and the return values are all the time AES-CBC encrypted utilizing the session key, then base64 encoded. The session secret&#8217;s RSA encrypted; the backdoor has a hardcoded non-public and public RSA key (not a pair) to deal with each instructions of the communication.<\/p>\n<p>A statically linked Crypto++ library is used to deal with the encryption and decryption operations.<\/p>\n<h5>C&amp;C communications<\/h5>\n<p>Operator instructions are transmitted within the <span style=\"font-family: courier new, courier, monospace;\">cookie<\/span> header (one other deviation from earlier variations, which used the URL or the HTTP request physique). PrimeCache responses are added to the HTTP response physique. If a file is being exfiltrated, the <span style=\"font-family: courier new, courier, monospace;\">Content material-Kind<\/span> header is about to <span style=\"font-family: courier new, courier, monospace;\">attachment<\/span>, matching the performance of the earlier variations.<\/p>\n<p>The PrimeCache predecessors additionally used the identical encryption scheme, and comparable parameter names (<span style=\"font-family: courier new, courier, monospace;\">a<\/span>, <span style=\"font-family: courier new, courier, monospace;\">c<\/span>, <span style=\"font-family: courier new, courier, monospace;\">f<\/span>, <span style=\"font-family: courier new, courier, monospace;\">okay<\/span>), however all had been despatched to the backdoor in a single request. The one supported instructions had been <span style=\"font-family: courier new, courier, monospace;\">r<\/span>, <span style=\"font-family: courier new, courier, monospace;\">u<\/span>, and <span style=\"font-family: courier new, courier, monospace;\">d<\/span>.<\/p>\n<h5>Hyperlinks with OilRig<a rel=\"nofollow\" target=\"_blank\" id=\"Links with OilRig\"\/><\/h5>\n<p>Once we evaluate PrimeCache with RDAT, as described within the <em><a rel=\"nofollow\" target=\"_blank\" href=\"#RDAT\">RDAT<\/a><\/em> attribution subsection, we see a number of similarities that assist our supposition that BladedFeline is a subgroup of OilRig.<\/p>\n<ul>\n<li>Each RDAT and PrimeCache use the Crypto++ library, and each parse the backdoor instructions utilizing the common expression <span style=\"font-family: courier new, courier, monospace;\">[^,]+<\/span>.\n<ul>\n<li>The payload makes an attempt to parse the decrypted cleartext utilizing the common expression <span style=\"font-family: courier new, courier, monospace;\">[^,]+<\/span> to get the command worth and the command arguments which might be break up with a comma.<\/li>\n<\/ul>\n<\/li>\n<li>Each share a operate, proven in Determine 1, that executes a shell command and reads the output, which, throughout our corpus, is discovered solely in these two items of malware.<\/li>\n<\/ul>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 1. A unique function to execute a shell command, shared between RDAT (left) and PrimeCache backdoors (right)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/bladedfeline\/figure-1.png\" alt=\"Figure 1. A unique function to execute a shell command\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. A novel operate to execute a shell command, shared between RDAT (left) and PrimeCache backdoors (proper)<\/em><\/figcaption><\/figure>\n<h4>Whisper backdoor<\/h4>\n<p>Whisper is a 32-bit Home windows binary written in C#\/.NET, named after its PDB strings <span style=\"font-family: courier new, courier, monospace;\">G:csharpWhisper_Trojan_winformWhisper_Trojan_winformWhisper_Trojan_winformobjReleaseVeaty.pdb<\/span> and <span style=\"font-family: courier new, courier, monospace;\">Z:csharpWhisper_Trojan_winform_for_releaseWhisper_Trojan_winformWhisper_Trojan_winformobjReleaseVeaty.pdb<\/span>. It makes use of a Microsoft Change server to speak with the attackers by sending e mail attachments through a compromised webmail account. We now have seen two variations of the backdoor: we detected and picked up one model, and was uploaded to VirusTotal from Iraq. These samples are nearly equivalent, however we had been in a position to decide the possible identification of the VirusTotal uploader primarily based on knowledge within the Whisper pattern and different samples uploaded by that person.<\/p>\n<p>Each these variations of Whisper have timestomped compilation timestamps (2090-04-11 23:38:14 and 2080-12-11 03:50:47). They&#8217;re constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/Fody\/Costura\" target=\"_blank\" rel=\"noopener\">Costura<\/a>, presumably to make sure that the sufferer\u2019s system makes use of the DLLs packaged with the binary and never DLLs within the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/framework\/app-domains\/gac\" target=\"_blank\" rel=\"noopener\">International Meeting Cache<\/a>.<\/p>\n<p>Whisper\u2019s operation shouldn&#8217;t be the primary time we&#8217;ve got noticed an OilRig subgroup utilizing cloud companies for its C&amp;C protocol. Whereas, not like with Whisper, there have been no emails really being despatched, Lyceum used e mail drafts for communication between its malware and operators all through 2022, as we described in a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/oilrig-persistent-attacks-cloud-service-powered-downloaders\/\" target=\"_blank\" rel=\"noopener\">earlier blogpost<\/a>.<\/p>\n<h5>Operational workflow<\/h5>\n<p>Whisper doesn&#8217;t require or settle for any arguments. As an alternative, its dropper \u2013 which we dubbed Whisper Protocol after its filename, <span style=\"font-family: courier new, courier, monospace;\">Protocol.pdf.exe<\/span> \u2013 writes its configuration file to disk alongside it (see the <em><a rel=\"nofollow\" target=\"_blank\" href=\"#Whisper Protocol\">Whisper Protocol<\/a> <\/em>part). The config file, proven in Determine 2, is in XML format with its key and worth strings base64 encoded. It&#8217;s known as by the <span style=\"font-family: courier new, courier, monospace;\">Specs<\/span> class of Whisper, which makes use of a operate \u2013 <span style=\"font-family: courier new, courier, monospace;\">DelockItems<\/span> \u2013 to base64 decode the config variables.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Whisper configuration file with its base64-encoded elements (left) and decoded (right)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/bladedfeline\/figure-2.jpeg\" alt=\"Figure 2. Whisper configuration file with its base64-encoded elements (left) and decoded (right)\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Whisper configuration file with its base64-encoded components (left) and decoded (proper)<\/em><\/figcaption><\/figure>\n<p>Determine 3 exhibits the operational circulation of Whisper, which we element within the following paragraphs.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 3. Basic operational flow of Whisper\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/bladedfeline\/figure-3.png\" alt=\"Figure 3. Basic operational flow of Whisper\" width=\"\" height=\"\"\/><figcaption><em>Determine 3. Primary operational circulation of Whisper<\/em><\/figcaption><\/figure>\n<p>Whisper\u2019s operational circulation will be damaged down into seven steps:<\/p>\n<p>In Step 1, Whisper makes use of the credentials from the config file (line 15 in Determine 2) and the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/microsoft.exchange.webservices.data.exchangeservice?view=exchange-ews-api\" target=\"_blank\" rel=\"noopener\">Microsoft Change Net Companies<\/a> class <span style=\"font-family: courier new, courier, monospace;\">ExchangeService<\/span> to try to log into compromised webmail accounts. As soon as Whisper efficiently logs into an account, it saves the credentials in reminiscence and writes the next to the log file <span style=\"font-family: courier new, courier, monospace;\">c:WindowsTempWindowsEventLogs.txt<\/span>:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">&#8212;&#8212;&#8212;&#8212; ItemContext is about: username [<username>] , use_defaultCred: [credentials&gt;]<\/username><\/span><\/p>\n<p>If no credentials within the config file are legitimate, Whisper logs the next error messages to the log file:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- there was No Approach to entry any MailBox.<\/span><\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">__________ Extraction operate is known as.<\/span><\/p>\n<p>If an surprising error is caught, Whisper writes the next to the log file (observe the misspelling of the phrase <span style=\"font-family: courier new, courier, monospace;\">occurred<\/span>, indicative of a non-native English speaker) and exits utilizing the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/system.environment.exit?view=net-8.0\" target=\"_blank\" rel=\"noopener\">Surroundings.Exit(Int32)<\/a> methodology. Unusually, the <span style=\"font-family: courier new, courier, monospace;\">exitCode<\/span> used, <span style=\"font-family: courier new, courier, monospace;\">0<\/span>, signifies that the method accomplished efficiently.<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-__ an unknown Exception happend. program turned off<\/span><\/p>\n<p>Subsequent, in Step 2, Whisper makes use of the credentials from the earlier step to examine for inbox guidelines utilizing the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/microsoft.exchange.webservices.data.exchangeservice.getinboxrules?view=exchange-ews-api\" target=\"_blank\" rel=\"noopener\">ExchangeService.GetInboxRules<\/a> methodology (which <em>[r]etrieves a group of Inbox guidelines which might be related to the desired person<\/em>). Utilizing the worth in line 13 of the configuration file (<span style=\"font-family: courier new, courier, monospace;\">key=&#8221;receive_sign&#8221;, worth=&#8221;PMO&#8221;<\/span>), Whisper iterates over the inbox guidelines in search of that worth to be laid out in certainly one of three locations: <span style=\"font-family: courier new, courier, monospace;\">topic<\/span>, <span style=\"font-family: courier new, courier, monospace;\">physique<\/span>, or <span style=\"font-family: courier new, courier, monospace;\">subjectorbody<\/span> and for emails matching that worth to be despatched to a specified location (<span style=\"font-family: courier new, courier, monospace;\">deleteditems<\/span> or <span style=\"font-family: courier new, courier, monospace;\">inbox<\/span>, relying on the model of Whisper). If the inbox has such a rule, Whisper goes to the following step; in any other case, Whisper creates a rule with the given parameters:<\/p>\n<ul>\n<li>Rule identify: <span style=\"font-family: courier new, courier, monospace;\">MicosoftDefaultRules<\/span>.<\/li>\n<li>Transfer to folder: <span style=\"font-family: courier new, courier, monospace;\">deleteditems<\/span> or <span style=\"font-family: courier new, courier, monospace;\">inbox<\/span>.\n<ul>\n<li>One model of Whisper specifies the <span style=\"font-family: courier new, courier, monospace;\">deleteditems<\/span> folder; the opposite factors to the <span style=\"font-family: courier new, courier, monospace;\">inbox<\/span>. Each are hardcoded within the separate binaries.<\/li>\n<\/ul>\n<\/li>\n<li>Mark as learn: <span style=\"font-family: courier new, courier, monospace;\">true<\/span>.<\/li>\n<li>Situation: <span style=\"font-family: courier new, courier, monospace;\">topic<\/span> comprises <span style=\"font-family: courier new, courier, monospace;\">PMO<\/span>.\n<ul>\n<li>The situation to search for the string, <span style=\"font-family: courier new, courier, monospace;\">topic<\/span>, is hardcoded in each variations of Whisper. The string to search for, <span style=\"font-family: courier new, courier, monospace;\">PMO<\/span>, is within the configuration file utilized by Whisper; we had been unable to gather the opposite configuration file.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>In Step 3, Whisper initiates a endless do loop that sends a check-in e mail message from the compromised e mail account in Step 1 to an e mail handle specified within the configuration file (line 16, <span style=\"font-family: courier new, courier, monospace;\">key=&#8221;alive_mail&#8221;<\/span>). The check-in message is shipped each 10 hours (line 10 within the configuration file, <span style=\"font-family: courier new, courier, monospace;\">key=&#8221;al_time&#8221;<\/span>; in minutes), the topic (line 17, <span style=\"font-family: courier new, courier, monospace;\">key=&#8221;alive_msg_subj&#8221;<\/span>) is <span style=\"font-family: courier new, courier, monospace;\">Content material<\/span>, and the message physique comprises the string outlined under:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">&#8220;Content material ID: &#8220;<\/span> + base64_encode(<span style=\"font-family: courier new, courier, monospace;\">&#8220;COMPUTERNAME:USERDNSDOMAIN:USERNAME&#8221;<\/span>)<\/p>\n<p>Subsequent, in Step 4, Whisper fetches operator instructions. It does so by looking the inbox recognized in Step 1 for information in a given folder (<span style=\"font-family: courier new, courier, monospace;\">deleteditems<\/span> or <span style=\"font-family: courier new, courier, monospace;\">inbox<\/span>, relying on the model of Whisper) with attachments the place the topic matches a string (provided within the configuration file; <span style=\"font-family: courier new, courier, monospace;\">PMO<\/span> in the one configuration file we collected). For matching emails with attachments, Whisper scrapes the attachment physique (which ought to include encrypted instructions) and shops the sender\u2019s e mail handle to be used later because the C&amp;C server to which operator command outcomes are uploaded.<\/p>\n<p>In Step 5, Whisper decrypts the operator instructions. It does so by first base64 decoding the string containing the command after which decrypting the consequence utilizing the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/system.security.cryptography.aes?view=net-8.0\" target=\"_blank\" rel=\"noopener\">.NET AES class<\/a> with a 16-byte initialization vector and the encryption key discovered within the configuration file (line 18, <span style=\"font-family: courier new, courier, monospace;\">key=&#8221;enc_key&#8221; worth=&#8221;cXdlcmFzZHp4Y3ZmZ2d0aGhsZGZvZ2g\/bHZtZ2xrZyE=&#8221;<\/span>). Decrypted instructions are within the type of <span style=\"font-family: courier new, courier, monospace;\"><cmd_id>;<command_to_execute\/><\/cmd_id><\/span>. The command ID, instructions, and command output are saved within the following format:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">base64-encoded(<command_id>: <cmd_id>n<cmd_output>n)<\/cmd_output><\/cmd_id><\/command_id><\/span><\/p>\n<p>Then, in Step 6, Whisper executes the backdoor instructions and information the outcomes. Potential instructions embody:<\/p>\n<p>The info written to disk is:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">that is my file content material<\/span><\/p>\n<p>The bytes to write down are base64 encoded (and decoded earlier than writing to disk). Profitable execution returns:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">file acquired correctly. wrote to: <filepath><filename\/><\/filepath><\/span><\/p>\n<ul>\n<li style=\"font-size: 1em;\">Ship a file to the C&amp;C server<\/li>\n<\/ul>\n<p>This command is prefixed with <span style=\"font-family: courier new, courier, monospace;\">that is my required file path<\/span> adopted by <span style=\"font-family: courier new, courier, monospace;\">n<unknown_variable>n<filepath><filename\/><\/filepath><\/unknown_variable><\/span>. Whisper reads the contents of the file into reminiscence, base64 encodes them, and returns:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">that is my required file <path>n<unknown_variable>n<filename>n<base64_encoded_file_contents\/><\/filename><\/unknown_variable><\/path><\/span><\/p>\n<ul>\n<li style=\"font-size: 1em;\">Execute a PowerShell script<\/li>\n<\/ul>\n<p>This command doesn&#8217;t have a prefix and as an alternative solely comprises a plaintext command that PowerShell is able to executing, postfixed with a pipe after which Whisper appends <span style=\"font-family: courier new, courier, monospace; white-space: nowrap;\">Out-String<\/span>. Output is saved on this type:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">base64-encoded(<command_id>: <cmd_id>n<cmd_output>n)<\/cmd_output><\/cmd_id><\/command_id><\/span><\/p>\n<p>Lastly, in Step 7, Whisper sends the command output in an e mail message to the C&amp;C inbox present in Step 4. The e-mail is formatted with these particulars:<\/p>\n<ul>\n<li>sending e mail handle: inbox from Step 1,<\/li>\n<li>recipient: e mail handle from Step 4,<\/li>\n<li>topic: <span style=\"font-family: courier new, courier, monospace;\">E-mail<\/span> (from the configuration file, line 14, <span style=\"font-family: courier new, courier, monospace;\">key=&#8221;send_sign&#8221;<\/span>),<\/li>\n<li>message physique: <span style=\"font-family: courier new, courier, monospace;\">Hey There! discover your ends in the attachment<\/span> (hardcoded within the binary), and<\/li>\n<li>attachment: output from the instructions in Step 6, encrypted with the identical encryption key in Step 5 (configuration file line 18, <span style=\"font-family: courier new, courier, monospace;\">key=&#8221;enc_key&#8221; worth=&#8221;cXdlcmFzZHp4Y3ZmZ2d0aGhsZGZvZ2g\/bHZtZ2xrZyE=&#8221;<\/span>).<\/li>\n<\/ul>\n<p>Steps 4\u20137 proceed in a loop utilizing the identical check-in schedule from Step 3 till the credentials hardcoded within the configuration file are modified.<\/p>\n<h4>Shahmaran backdoor<\/h4>\n<p>The Shahmaran backdoor, named after a legendary half-snake, half-woman creature from <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Shahmaran\" target=\"_blank\" rel=\"noopener\">Iranian folklore<\/a>, is a 64-bit PE that was discovered within the startup folder as:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">%ROAMINGAPPDATApercentMicrosoftWindowsStart MenuProgramsStartupadobeupdater.exe<\/span><\/p>\n<p>At system startup, Shahmaran creates a Home windows <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/synchapi\/nf-synchapi-createeventw\" target=\"_blank\" rel=\"noopener\">occasion object<\/a>, <span style=\"font-family: courier new, courier, monospace;\">SysPrep<\/span>. It&#8217;s potential that the Shahmaran builders selected <span style=\"font-family: courier new, courier, monospace;\">SysPrep<\/span> because the occasion identify to mix into the background noise, as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/manufacture\/desktop\/sysprep--system-preparation--overview?view=windows-11\" target=\"_blank\" rel=\"noopener\">SysPrep<\/a> is a part of the Home windows imaging course of. Home windows admins use it to create an ordinary Home windows picture (also known as a Gold or Golden picture) earlier than deployment to enterprise methods. Determine 4 exhibits the <span style=\"font-family: courier new, courier, monospace;\">SysPrep<\/span> occasion object on a compromised system as seen by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/winobj\" target=\"_blank\" rel=\"noopener\">Sysinternals\u2019 WinObj<\/a>.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 4. Sysinternals\u2019 WinObj showing the SysPrep event object on a compromised system\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/bladedfeline\/figure-4.jpeg\" alt=\"Figure 4. Sysinternals\u2019 WinObj showing the SysPrep event object on a compromised system\" width=\"\" height=\"\"\/><figcaption><em>Determine 4. Sysinternals\u2019 WinObj displaying the <\/em><span style=\"font-family: courier new, courier, monospace;\">SysPrep<\/span> <em>occasion object on a compromised system<\/em><\/figcaption><\/figure>\n<p>The C&amp;C area is hardcoded, <span style=\"font-family: courier new, courier, monospace;\">olinpa[.]com<\/span>, as is the port, <span style=\"font-family: courier new, courier, monospace;\">80<\/span>, and the Person-Agent string, of which there are two. The preliminary connection to the C&amp;C makes use of an incomplete Person-Agent string (it&#8217;s lacking the closing parenthesis):<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">Mozilla\/4.0 (appropriate; MSIE 6.0; Home windows NT 5.0<\/span><\/p>\n<p>Subsequent communication with the C&amp;C makes use of the corrected Person-Agent string:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">Mozilla\/4.0 (appropriate; MSIE 6.0; Home windows NT 5.0)<\/span><\/p>\n<p>Shahmaran doesn&#8217;t use any compression or encryption for community communications. And whereas the port is hardcoded (<span style=\"font-family: courier new, courier, monospace;\">80<\/span>), there are code fragments that examine for the port in use and replace communication variables if port <span style=\"font-family: courier new, courier, monospace;\">443<\/span> is used.<\/p>\n<p>After checking in with the C&amp;C server, Shahmaran executes any operator instructions offered, returns any output from these instructions, then sleeps for 30 seconds earlier than checking in with the C&amp;C server once more, advert infinitum. Desk 3 exhibits the accessible operator instructions and their capabilities.<\/p>\n<p style=\"text-align: center;\"><em>Desk 3. Operator instructions and their descriptions<\/em><\/p>\n<table border=\"1\" width=\"643\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><strong>Operator command<\/strong><\/td>\n<td style=\"width: 421px;\" width=\"426\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">1 <path\/><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Returns the datetime that the desired file was written to disk in UTC, prepended with <span style=\"font-family: courier new, courier, monospace;\">id=<\/span> and within the format <span style=\"font-family: courier new, courier, monospace;\">YYYY\/MM\/DD HH:MM:SS<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">2 <filename><source><destination\/><\/source><\/filename><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Strikes the desired file to the desired location. Returns the output of the file transfer operation prepended with <span style=\"font-family: courier new, courier, monospace;\">id=<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">3 <path\/><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Deletes the desired file. Returns the output of the file delete operation prepended with <span style=\"font-family: courier new, courier, monospace;\">id=<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">4 <path\/><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Creates the desired listing. Returns the output of the listing creation operation prepended with <span style=\"font-family: courier new, courier, monospace;\">id=<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">5<\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Creates a log file within the hardcoded location <span style=\"font-family: courier new, courier, monospace;\">c:programdata~tmp.log<\/span>, if it doesn&#8217;t exist already.<br \/>If the file already exists, reads the contents and returns them to the C&amp;C server with the file\u2019s timestamp in UTC and within the format <span style=\"font-family: courier new, courier, monospace;\">YYYY\/MM\/DD HH:MM:SS<\/span>, then deletes the file.<br \/>If the file doesn&#8217;t exist, returns the filename and path.<br \/>If an error happens, returns the error.<br \/>All returned knowledge is prepended with <span style=\"font-family: courier new, courier, monospace;\">s=<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">6 <path> <data\/><\/path><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Checks for the desired file. If discovered, writes the offered knowledge to the file and returns <span style=\"font-family: courier new, courier, monospace;\">s=<provided_filename\/><\/span>. If not discovered, returns <span style=\"font-family: courier new, courier, monospace;\">u=<error_code\/><\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">7 <path\/><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Creates the desired file. Returns <span style=\"font-family: courier new, courier, monospace;\">s=<\/span> appended with both the filename (success) or an error code.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 215px;\" width=\"217\"><span style=\"font-family: courier new, courier, monospace;\">8 <path\/><\/span><\/td>\n<td style=\"width: 421px;\" width=\"426\">Checks for the presence of the desired filename in a compressed folder within the specified location on disk and creates it if it doesn&#8217;t exist. Returns <span style=\"font-family: courier new, courier, monospace;\">s=<\/span> appended with the filename and the timestamp in UTC within the format <span style=\"font-family: courier new, courier, monospace;\">YYYY\/MM\/DD HH:MM:SS<\/span>. The timestamp is used to find out whether or not the file was already current or was simply created.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>After executing an operator command, Shahmaran sends the output to the C&amp;C server utilizing the format <span style=\"font-family: courier new, courier, monospace;\">t=<operator_command>&amp;<command_output\/><\/operator_command><\/span>, equivalent to <span style=\"font-family: courier new, courier, monospace;\">t=1&amp;s=<file_timestamp\/><\/span>.<\/p>\n<h4>Slippery Snakelet backdoor<\/h4>\n<p>Slippery Snakelet is a small Python-based backdoor with restricted capabilities:<\/p>\n<p style=\"mso-list: l10 level1 lfo3;\">1. executes a command through <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span>,<\/p>\n<p style=\"mso-list: l10 level1 lfo3;\">2. downloads a file from a URL, and<\/p>\n<p style=\"mso-list: l10 level1 lfo3;\">3. add a file to the <span style=\"font-family: courier new, courier, monospace;\">\/newfile\/<\/span> URI path.<\/p>\n<p>Slippery Snakelet has a hardcoded C&amp;C server, <span style=\"font-family: courier new, courier, monospace;\">zaincell[.]retailer<\/span>, and communicates with it through URLs of the shape <span style=\"font-family: courier new, courier, monospace;\">https:\/\/zaincell[.]retailer\/request\/<uid\/><\/span>, the place the <span style=\"font-family: courier new, courier, monospace;\"><uid\/><\/span> is the sufferer\u2019s login area and the compromised pc\u2019s identify separated by a interval then base64 encoded (e.g., <span style=\"font-family: courier new, courier, monospace;\">victim_domain.computer_name = dmljdGltX2RvbWFpbi5jb21wdXRlcl9uYW1l<\/span>).<\/p>\n<p>Slippery Snakelet additionally has this hardcoded Person-Agent:<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">Mozilla\/5.0 (Home windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/88.0.4324.104 Safari\/537.36<\/span><\/p>\n<p>The C&amp;C server was disguised as an <span style=\"font-family: courier new, courier, monospace;\">Arabian Gulf E-Studying<\/span> web site and the default HTML touchdown web page doesn&#8217;t include any instructions. When Slippery Snakelet provides a accurately formatted request (e.g., <span style=\"font-family: courier new, courier, monospace;\">https:\/\/zaincell[.]retailer\/request\/<uid\/><\/span>), the C&amp;C server inserts <span style=\"font-family: courier new, courier, monospace;\"><code\/><\/span> tags equivalent to <span style=\"font-family: courier new, courier, monospace;\"><code>6wjTyB3Y20KSzU1VUlTagp3aG9hbWkKbnVsbApudWxs<\/code><\/span> into the web page, and Slippery Snakelet collects and decodes these.<\/p>\n<p>Slippery Snakelet base64 decodes the whole lot from the eighth character to the top of the string (i.e., <span style=\"font-family: courier new, courier, monospace;\">Y20KSzU1VUlTagp3aG9hbWkKbnVsbApudWxs<\/span> within the instance above). The decoded output is newline separated and comprises the 5 gadgets described in Desk 4<\/p>\n<p style=\"text-align: center;\"><em>Desk 4. Slippery Snakelet arguments and choices<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"208\"><strong>Instructions<\/strong><\/td>\n<td width=\"265\"><strong>Choices<\/strong><\/td>\n<td width=\"170\"><strong>Instance<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"208\"><strong>Command Kind<\/strong><\/td>\n<td width=\"265\"><span style=\"font-family: courier new, courier, monospace;\">cm<\/span> (execute <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span> command)<br \/><span style=\"font-family: courier new, courier, monospace;\">getfl<\/span> (obtain a file)<br \/><span style=\"font-family: courier new, courier, monospace;\">sendfl<\/span> (add a file)<\/td>\n<td width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">cm<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"208\"><strong>Command ID<\/strong><\/td>\n<td width=\"265\">CMID (a random string)<\/td>\n<td width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">K55UISj<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"208\"><strong>Command | FileUrl | FilePath<\/strong><\/td>\n<td width=\"265\">Respectively for <span style=\"font-family: courier new, courier, monospace;\">cm | getfl | sendfl<\/span><\/td>\n<td width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">whoami<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"208\"><strong>Null | SavePath | FilePath<\/strong><\/td>\n<td width=\"265\">Respectively for <span style=\"font-family: courier new, courier, monospace;\">cm | getfl | sendfl<\/span><\/td>\n<td width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">null<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"208\"><strong>Null<\/strong><\/td>\n<td width=\"265\">Unknown<\/td>\n<td width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">null<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>Laret and Pinar \u2013 reverse tunnels<\/h4>\n<p>Laret and Pinar, whose names are derived from the inner names in every respective file, are 32-bit Home windows binaries written in C#\/.NET. Each have timestomped PE compilation timestamps \u2013 a tactic that&#8217;s widespread amongst Center Japanese (and significantly Iran-nexus) risk teams \u2013 of 2058-02-07 00:12:48 and 2072-07-10 18:26:15, respectively. Each had been discovered on two methods on the places in Desk 5.<\/p>\n<p style=\"text-align: center;\"><em>Desk 5. Areas of Laret and Pinar on disk, together with filenames<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"58\"><strong>Reverse tunnel<\/strong><\/td>\n<td width=\"226\"><strong>Location<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"2\" width=\"58\"><strong>Laret<\/strong><\/td>\n<td width=\"226\"><span style=\"font-family: courier new, courier, monospace;\">%APPDATApercentLocalLEAP DesktopLEAPForm.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"226\"><span style=\"font-family: courier new, courier, monospace;\"><unknown_location>wincapsrv.exe<\/unknown_location><\/span><\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"58\"><strong>Pinar<\/strong><\/td>\n<td width=\"226\"><span style=\"font-family: courier new, courier, monospace;\">C:Program FilesLEAP OfficeSystemMain.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"226\"><span style=\"font-family: courier new, courier, monospace;\">C:Program FilesLEAP Officewinhttpproxy.exe<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"margin-top: 12.0pt;\">Within the case the place we don&#8217;t have a location on disk for Laret however we do have the filename (<span style=\"font-family: courier new, courier, monospace;\">wincapsrv.exe<\/span>), we may see that Laret was downloaded from <span style=\"font-family: courier new, courier, monospace;\">http:\/\/178.209.51[.]61:8000\/wincapsrv.exe<\/span> through PowerShell. Sadly, we didn&#8217;t handle to find the place it was written to disk. Makes an attempt to enumerate the IP and obtain the file had been rebuffed by the C&amp;C server, possible indicating that some type of compromised host identification is required within the connection setup (which we don&#8217;t have).<\/p>\n<p>Relating to writing to disk, BladedFeline operators possible timestomped the file creation date of Pinar to 2017-09-14 14:56:00 on one of many two compromised methods. How the file creation date was timestomped is an open query, however it exhibits that the attackers have compromised these two methods to such an extent that they most likely have administrative rights.<\/p>\n<p>At runtime, each Laret and Pinar depend on a configuration file in the identical listing as their binaries for eight required variables, that are listed in Desk 6.<\/p>\n<p style=\"text-align: center;\"><em>Desk 6. Laret and Pinar configuration parameters with default hardcoded values<\/em><\/p>\n<table style=\"height: 450px;\" border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><strong>Area<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"387\"><strong>Description<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"104\"><strong>Default\u00a0worth<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">ssh_host<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">C&amp;C IP handle.<\/td>\n<td style=\"height: 50px;\" width=\"104\">N\/A<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">ssh_port<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">\u00a0<\/td>\n<td style=\"height: 50px;\" width=\"104\"><span style=\"font-family: courier new, courier, monospace;\">22<\/span><\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">ssh_username<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">C&amp;C username.<\/td>\n<td style=\"height: 50px;\" width=\"104\">N\/A<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">ssh_pass<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">C&amp;C password.<\/td>\n<td style=\"height: 50px;\" width=\"104\">N\/A<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">local_port<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">\u00a0<\/td>\n<td style=\"height: 50px;\" width=\"104\"><span style=\"font-family: courier new, courier, monospace;\">9666<\/span><\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">process_file<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">File to execute earlier than executing any reverse tunnel actions.<\/td>\n<td style=\"height: 50px;\" width=\"104\">N\/A<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">wait_time_minutes<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">Time to attend between check-ins with the C&amp;C server.<\/td>\n<td style=\"height: 50px;\" width=\"104\"><span style=\"font-family: courier new, courier, monospace;\">10f<\/span> (271)<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">remote_port<\/span><\/td>\n<td style=\"height: 50px;\" width=\"387\">Port quantity used for port forwarding.<\/td>\n<td style=\"height: 50px;\" width=\"104\"><span style=\"font-family: courier new, courier, monospace;\">1234<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We now have to date not collected the configuration file however have reconstructed its possible content material, present in Determine 5, primarily based on code evaluation. Studying from the configuration file is completed by base64 decoding the encoded string to bytes, which ends up in strings of space-delimited, hexadecimal-encoded character values, which in flip are decoded into ASCII strings.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 5. Example contents of the configuration file used by Laret and Pinar reverse tunnels\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/bladedfeline\/figure-5.jpeg\" alt=\"Figure 5. Example contents of the configuration file used by Laret and Pinar reverse tunnels\" width=\"\" height=\"\"\/><figcaption><em>Determine 5. Instance contents of the configuration file utilized by Laret and Pinar reverse tunnels<\/em><\/figcaption><\/figure>\n<p>The BladedFeline builders check with this as <span style=\"font-family: courier new, courier, monospace;\">Delocking<\/span> and the alternative (writing to the configuration file) as <span style=\"font-family: courier new, courier, monospace;\">Enlocking<\/span>. This most likely signifies a passing familiarity with English, however the builders had been removed from proficient. Different examples of weak translation expertise embody:<\/p>\n<ul>\n<li><span style=\"font-family: courier new, courier, monospace;\">time Alapsed and consumer not linked<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">aerpoo after<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">Ready connection &#8230;<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">error in creaate ssh consumer<\/span><\/li>\n<\/ul>\n<p>Apparently, at one other level within the reverse tunnels, the builders accurately spelled the phrase elapsed (<span style=\"font-family: courier new, courier, monospace;\">time elapsed!<\/span>), which is indicative of poor coding and lax code evaluation, if any is carried out (e.g., there&#8217;s quite a lot of command consequence textual content output to the command line, as if the reverse tunnels had been shipped instantly after profitable testing was accomplished).<\/p>\n<p>The precise operate and circulation of Laret and Pinar after accumulating the parameters from the configuration file is sort of banal, however that&#8217;s most likely an intentional effort to mix in. Each search for a filename within the <span style=\"font-family: courier new, courier, monospace;\">process_file<\/span> parameter and, if a file matching the provided identify is current, execute it and begin two threads:<\/p>\n<ol>\n<li>Units up an SSH connection to the C&amp;C IP within the configuration file utilizing the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.nuget.org\/packages\/Core.Renci.SshNet\/\" target=\"_blank\" rel=\"noopener\">Core.Renci.SshNet<\/a> DLL included inside the binary. Port <span style=\"font-family: courier new, courier, monospace;\">22<\/span> is hardcoded because the C&amp;C port and port forwarding can also be enabled, utilizing the <span style=\"font-family: courier new, courier, monospace;\">remote_port<\/span> variable from the configuration file.<\/li>\n<li>Units up a listener on the port specified within the <span style=\"font-family: courier new, courier, monospace;\">local_port<\/span> parameter of the configuration file. Notice that any knowledge despatched to the listener is completed within the clear (i.e., no encryption or obfuscation is used past additional <span style=\"font-family: courier new, courier, monospace;\">\u0000<\/span> characters which might be eliminated on the time of receipt by Laret and Pinar).<\/li>\n<\/ol>\n<p>If no file is laid out in <span style=\"font-family: courier new, courier, monospace;\">process_file<\/span>, each Laret and Pinar skip establishing a listener port.<\/p>\n<p>Laret and Pinar solely differ considerably in that Pinar units up a service, known as <span style=\"font-family: courier new, courier, monospace;\">Service1<\/span>, for persistence previous to executing the 2 threads. Laret has no technique of persistence past its course of operating indefinitely.<\/p>\n<h4>Supplementary instruments<\/h4>\n<h5>Flog webshell<\/h5>\n<p>Flog is a webshell discovered uploaded to VirusTotal from Iraq by the identical submitter who uploaded one of many variations of Whisper. Based mostly on that and the shut timeframe (each had been uploaded inside a matter of minutes) we consider it was deployed by BladedFeline to the sufferer within the Iraq authorities.<\/p>\n<p>Flog, so named for its filename \u2013 <span style=\"font-family: courier new, courier, monospace;\">flogon.aspx<\/span> \u2013 appears for particular enter from the BladedFeline operators of the shape <span style=\"font-family: courier new, courier, monospace;\"><password>=&lt;(a|b|c|d)&gt;#<path\/><\/password><\/span><\/p>\n<p>Flog hashes the password, which should match the MD5 checksum <span style=\"font-family: courier new, courier, monospace;\">4CC88CE123B0DA8D75C0FE66A39339F6<\/span>.<\/p>\n<p>Variables (<span style=\"font-family: courier new, courier, monospace;\">a|b|c|d<\/span>) are command choices:<\/p>\n<ul>\n<li><span style=\"font-family: courier new, courier, monospace;\">a<\/span> returns, for the trail offered, a listing itemizing and the byte size of every file,<\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">b<\/span> creates a file on disk, utilizing the trail offered,<\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">c<\/span> splits the trail variable on a pipe and writes a file to disk the place the primary a part of the trail is the filename and the second half is the information to write down, and<\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">d<\/span> deletes a specified file given within the provided path.<\/li>\n<\/ul>\n<h5>Hawking Listener<\/h5>\n<p>Hawking Listener, so named for its PDB string \u2013 <span style=\"font-family: courier new, courier, monospace;\">C:Usersg18u04sourcereposHawkingHawkingobjReleaselistner.pdb<\/span> \u2013 is a 32-bit .NET\/C# Home windows binary with a timestomped compilation time of 2057-11-14 16:59:12. It was additionally uploaded to VirusTotal by the identical person who uploaded Flog and might be a BladedFeline software. It implements the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/system.net.httplistener?view=net-8.0\" target=\"_blank\" rel=\"noopener\">.NET HTTPListener class<\/a> to arrange a listener with a hardcoded URL (which we can not disclose on this case with out revealing the identification of the sufferer). Alternatively, Hawking will be offered at runtime with URLs for the listener socket to watch.<\/p>\n<p>Hawking listens for a offered <span style=\"font-family: courier new, courier, monospace;\">QueryString<\/span> (from a BladedFeline operator) with <span style=\"font-family: courier new, courier, monospace;\">snmflwkejrhgsey<\/span> as the important thing within the key-value pair. As soon as acquired, Hawking executes the worth in <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span> and returns the output. To cease Hawking, operators want solely ship <span style=\"font-family: courier new, courier, monospace;\">cease<\/span> as the important thing within the <span style=\"font-family: courier new, courier, monospace;\">QueryString<\/span> with a non-null variable within the worth.<\/p>\n<p>Hawking logs all interactions, runtime arguments, and command output to the file <span style=\"font-family: courier new, courier, monospace;\">log.txt<\/span> in its working listing.<\/p>\n<h5>P.S. Olala<\/h5>\n<p>P.S. Olala is a 32-bit .NET binary named for its meant operate (executing PowerShell scripts) and its PDB path <span style=\"font-family: courier new, courier, monospace;\">G:csharppsExecuterServiceewsServiceobjReleaseOlala.pdb<\/span>. It doesn&#8217;t settle for any runtime arguments. Relatively, at runtime, P.S. Olala makes use of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/system.serviceprocess.servicebase.run?view=dotnet-plat-ext-8.0#system-serviceprocess-servicebase-run(system-serviceprocess-servicebase())\" target=\"_blank\" rel=\"noopener\">Run(ServiceBase[])<\/a> methodology of the .NET <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/api\/system.serviceprocess.servicebase?view=dotnet-plat-ext-8.0\" target=\"_blank\" rel=\"noopener\">ServiceBase<\/a> class to register itself as a service with the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/services\/service-control-manager\" target=\"_blank\" rel=\"noopener\">Service Management Supervisor<\/a> (for persistence).<\/p>\n<p>When the P.S. Olala service is known as, it spawns a thread and executes the operate <span style=\"font-family: courier new, courier, monospace;\">mainLoop<\/span>, proven in Determine 6. Primarily, P.S. Olala is an executor of the PowerShell script saved in <span style=\"font-family: courier new, courier, monospace;\">%APPDATApercentLocalMicrosoftInputPersonalizationTrainedDataStore.ps1<\/span>.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 6. The main function of P.S. Olala\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/bladedfeline\/figure-6.png\" alt=\"Figure 6. The main function of P.S. Olala\" width=\"\" height=\"\"\/><figcaption><em>Determine 6. The primary operate of P.S. Olala<\/em><\/figcaption><\/figure>\n<p>Sadly, we had been unable to gather any of the <span style=\"font-family: courier new, courier, monospace;\">TrainedDataStore.ps1<\/span> scripts. Nonetheless, contextual data signifies it&#8217;s possible an executor of the Whisper backdoor, or one of many reverse tunnels (Laret or Pinar). Your entire circulation (P.S. Olala \u2192 TrainedDataStore \u2192 Whisper\/Laret\/Pinar) might be an elongated persistence chain aiming to keep up entry.<\/p>\n<h5>Sheep Tunneler<\/h5>\n<p>Sheep Tunneler, a customized tunneling software that we named primarily based on the PDB string <span style=\"font-family: courier new, courier, monospace;\">C:UserssheepsourcereposMPMPobjReleaseMP.pdb<\/span>), has been noticed within the two following places:<\/p>\n<ul>\n<li><span style=\"font-family: courier new, courier, monospace;\">%APPDATApercentLocalMicrosoftWindowsRingtonesRingService.exe<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">%APPDATApercentLocalMicrosoftWindowsShellmspsrv.exe<\/span><\/li>\n<\/ul>\n<p>Sheep Tunneler will be executed in two modes: community tunneling (by utilizing the runtime argument <span style=\"font-family: courier new, courier, monospace;\">center<\/span>) or join again (by utilizing the arguments <span style=\"font-family: courier new, courier, monospace;\">cb <ip>:<port\/><\/ip><\/span>).<\/p>\n<h5>Whisper Protocol<a rel=\"nofollow\" target=\"_blank\" id=\"Whisper Protocol\"\/><\/h5>\n<p>Whisper Protocol, so named for its filename (<span style=\"font-family: courier new, courier, monospace;\">Protocol.pdf.exe<\/span>) is a 64-bit Python-compiled Home windows binary with a compilation timestamp of 2024-03-11 09:01:20. It creates a folder in <span style=\"font-family: courier new, courier, monospace;\">C:ProgramDataVeeamUpdate<\/span> and writes each Whisper and its configuration file to that folder. Whisper Protocol additionally copies itself to <span style=\"font-family: courier new, courier, monospace;\">%APPDATApercentRoamingMicrosoftWindowsStart MenuProgramsStartupVeeamUpdate.lnk<\/span> for persistence. Lastly, it executes Whisper and exits gracefully.<\/p>\n<h2>Conclusion<\/h2>\n<p>BladedFeline is a sophisticated risk group that focuses on focusing on Iraqi and Kurdish victims, particularly governmental officers and organizations. We assess that the group is probably going a subgroup of OilRig. We look forward to finding that BladedFeline will stick with implant growth as a way to keep and broaden entry inside its compromised sufferer set, possible for cyberespionage.<\/p>\n<blockquote>\n<div><em>For any inquiries about our analysis revealed on WeLiveSecurity, please contact us at <a rel=\"nofollow\" target=\"_blank\" style=\"background-color: #f4f4f4;\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/bladedfeline-whispering-dark\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.\u00a0<\/em><\/div>\n<div><em>ESET Analysis provides non-public APT intelligence experiences and knowledge feeds. For any inquiries about this service, go to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=bladedfeline-whispering-dark&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> web page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<h3>Information<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"179\"><strong>SHA-1<\/strong><\/td>\n<td width=\"142\"><strong>Filename<\/strong><\/td>\n<td width=\"132\"><strong>Detection<\/strong><\/td>\n<td width=\"189\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">01B99FF47EC6394753F9<wbr\/>CCDD2D43B3E804F9EE36<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">Avamer.pdf.exe<\/span><\/td>\n<td width=\"132\">Python\/Trojan<wbr\/>Dropper.Agent.GI<\/td>\n<td width=\"189\">Python-compiled dropper for Spearal<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">1C757ACCBC2755E83E53<wbr\/>0DDA11B3F81007325E67<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">Win_Updates.exe<\/span><\/td>\n<td width=\"132\">MSIL\/Agent.EUM<\/td>\n<td width=\"189\">Spearal, a BladedFeline backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">272CF34E8DB2078A3170<wbr\/>CF0E54255D89785E3C50<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">scr8B45.ps1<\/span><\/td>\n<td width=\"132\">PowerShell\/Trojan<wbr\/>Dropper.Agent.AJU<\/td>\n<td width=\"189\">PowerShell script to put in Spearal.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">37859E94086EC47B3665<wbr\/>328E9C9BAF665CB869F6<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">ncms_demo.msi<\/span><\/td>\n<td width=\"132\">MSIL\/Agent.EUM<\/td>\n<td width=\"189\">MSI contained in the zip archive that drops and executes a PowerShell script that in flip drops and executes Spearal.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">3D21E1C9DFBA38EC6997<wbr\/>AE6E426DF9291F89762A<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">flogon.aspx<\/span><\/td>\n<td width=\"132\">ASP\/Agent.BI<\/td>\n<td width=\"189\">Flog webshell.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">4954E8ACE23B48EC55F1<wbr\/>FF3A47033351E9FA2D6C<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">winsmsrv.exe<\/span><\/td>\n<td width=\"132\">MSIL\/HackTool<wbr\/>.Agent.YN<\/td>\n<td width=\"189\">Pinar, a reverse tunnel.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">562E1678EC8FDC1D83A3<wbr\/>F73EB511A6DDA08F3B3D<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">LogonUl.exe<\/span><\/td>\n<td width=\"132\">Win64\/OilRig_<wbr\/>AGen.A<\/td>\n<td width=\"189\">RDAT backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">66BD8DB40F4169C7F0FC<wbr\/>A3D5D15C978EFE143CF8<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">Protocol.pdf.exe<\/span><\/td>\n<td width=\"132\">Python\/Trojan<wbr\/>Dropper.Agent.FT<\/td>\n<td width=\"189\">Whisper Protocol, the dropper that writes and executes the Whisper backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">6973D3FF8852A3292380<wbr\/>B07858D43D0B80C0616E<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">VeeamUpdate.exe<\/span><\/td>\n<td width=\"132\">MSIL\/Agent.ERR<\/td>\n<td width=\"189\">Whisper backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">73D0FAA475C6E489B2C5<wbr\/>C95BB51DEDE4719D199E<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">winhttpproxy.exe<\/span><\/td>\n<td width=\"132\">MSIL\/HackTool<wbr\/>.Agent.XY<\/td>\n<td width=\"189\">Pinar, a reverse tunnel.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">B8AFC21EF2AA854896B9<wbr\/>7F1C81B376DCDDE2466D<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">RunExeActionAllowed<wbr\/>Listing.exe<\/span><\/td>\n<td width=\"132\">MSIL\/Agent.ERR<\/td>\n<td width=\"189\">Whisper backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">BB4FFCDBFAD40125080C<wbr\/>13FA4917A1E836A8D101<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">MFTD.exe<\/span><\/td>\n<td width=\"132\">MSIL\/Tiny.GL<\/td>\n<td width=\"189\">Hawking Listener.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">BE0AD25B7B4834798490<wbr\/>8175404996531CFD74B7<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">videosrv.exe<\/span><\/td>\n<td width=\"132\">Generik.BKYYERR<\/td>\n<td width=\"189\">VideoSRV, a reverse shell.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">E8E6E6AFEF3F574C1F52<wbr\/>28BDB28ABB34F8A0D09A<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">wincapsrv.exe<\/span><\/td>\n<td width=\"132\">MSIL\/HackTool<wbr\/>.Agent.XY<\/td>\n<td width=\"189\">Laret, a reverse tunnel.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">F28D8C5C2283019E6ED7<wbr\/>88D20240ABC8554CADB5<\/span><\/td>\n<td width=\"142\">N\/A<\/td>\n<td width=\"132\">MSIL\/Agent.EUM<\/td>\n<td width=\"189\">Zip archive that comprises an MSI that drops and executes a PowerShell script that in flip drops and executes Spearal.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Community<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"141\"><strong>IP<\/strong><\/td>\n<td width=\"76\"><strong>Area<\/strong><\/td>\n<td width=\"123\"><strong>Internet hosting supplier<\/strong><\/td>\n<td width=\"85\"><strong>First seen<\/strong><\/td>\n<td width=\"218\"><strong>Particulars<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"141\"><span style=\"font-family: courier new, courier, monospace;\">178.209.51[.]61<\/span><\/td>\n<td width=\"76\">N\/A<\/td>\n<td width=\"123\">9 Web Options AG<\/td>\n<td width=\"85\">2023\u201112\u201118<\/td>\n<td width=\"218\">Distribution server for BladedFeline\u2019s Laret reverse tunnel.<\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: courier new, courier, monospace;\">185.76.78[.]177<\/span><\/td>\n<td>N\/A<\/td>\n<td>EDIS GmbH &#8211; Noc Engineer<\/td>\n<td>N\/A<\/td>\n<td>C&amp;C utilized by Spearal.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>MITRE ATT&amp;CK strategies<\/h2>\n<p>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\" target=\"_blank\" rel=\"noopener\">model 17<\/a>\u00a0of the MITRE ATT&amp;CK framework<strong>.<\/strong><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Identify<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"113\"><strong>Reconnaissance<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1595\/002\">T1595.002<\/a><\/td>\n<td width=\"151\">Energetic Scanning: Vulnerability Scanning<\/td>\n<td width=\"265\">BladedFeline most likely conducts vulnerability scanning towards targets to determine probably weak, uncovered functions.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Useful resource Improvement<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1583\/001\">T1583.001<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Domains<\/td>\n<td width=\"265\">BladedFeline registers domains to make use of for C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1583\/003\">T1583.003<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Digital Non-public Server<\/td>\n<td width=\"265\">BladedFeline makes use of VPS companies to host C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1583\">T1583<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure<\/td>\n<td width=\"265\">BladedFeline makes use of IPs for community infrastructure, together with distributing malware and C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1586\/002\">T1586.002<\/a><\/td>\n<td width=\"151\">Compromise Accounts: E-mail Accounts<\/td>\n<td width=\"265\">BladedFeline makes use of compromised e mail accounts as C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Preliminary Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1190\">T1190<\/a><\/td>\n<td width=\"151\">Exploit Public-Going through Software<\/td>\n<td width=\"265\">BladedFeline most likely exploits weak public-facing functions for preliminary entry.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1059\/003\">T1059.003<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: Home windows Command Shell<\/td>\n<td width=\"265\">BladedFeline makes use of the Home windows Command Shell to execute instructions on compromised endpoints.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1059\/007\">T1059.007<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: JavaScript<\/td>\n<td width=\"265\">BladedFeline makes use of JavaScript webshells to execute instructions on compromised endpoints.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1059\/001\">T1059.001<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: PowerShell<\/td>\n<td width=\"265\">BladedFeline makes use of PowerShell to execute instructions on compromised endpoints.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1059\/006\">T1059.006<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: Python<\/td>\n<td width=\"265\">BladedFeline makes use of Python as a dropper for deploying backdoors to compromised endpoints.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1559\">T1559<\/a><\/td>\n<td width=\"151\">Inter-Course of Communication<\/td>\n<td width=\"265\">BladedFeline makes use of IPC as a way of native code execution in its malicious IIS module.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1569\/002\">T1569.002<\/a><\/td>\n<td width=\"151\">System Companies: Service Execution<\/td>\n<td width=\"265\">BladedFeline makes use of Home windows companies for malware execution with Whisper and PrimeCache.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Persistence<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1547\/001\">T1547.001<\/a><\/td>\n<td width=\"151\">Boot or Logon Autostart Execution: Registry Run Keys \/ Startup Folder<\/td>\n<td width=\"265\">The Whisper backdoor creates a LNK file within the startup folder for persistence.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1546\">T1546<\/a><\/td>\n<td width=\"151\">Occasion Triggered Execution<\/td>\n<td width=\"265\">PrimeCache is loaded by an IIS Employee Course of (<span style=\"font-family: courier new, courier, monospace;\">w3wp.exe<\/span>) when the IIS server receives an inbound HTTP request.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Protection Evasion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1078\">T1078<\/a><\/td>\n<td width=\"151\">Legitimate Accounts<\/td>\n<td width=\"265\">BladedFeline makes use of professional accounts to exfiltrate knowledge and bypass defenses, and as C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1140\">T1140<\/a><\/td>\n<td width=\"151\">Deobfuscate\/Decode Information or Data<\/td>\n<td width=\"265\">The Whisper backdoor makes use of base64 encoding to obfuscate knowledge.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1070\/004\">T1070.004<\/a><\/td>\n<td width=\"151\">Indicator Elimination: File Deletion<\/td>\n<td width=\"265\">The Python dropper for Whisper deletes itself and different set up information after a profitable set up.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1070\/006\">T1070.006<\/a><\/td>\n<td width=\"151\">Indicator Elimination: Timestomp<\/td>\n<td width=\"265\">BladedFeline routinely timestomps the compilation timestamps of malware that the group develops.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Credential Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1003\/001\">T1003.001<\/a><\/td>\n<td width=\"151\">OS Credential Dumping: LSASS Reminiscence<\/td>\n<td width=\"265\">BladedFeline dumps LSASS from reminiscence to steal credentials.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1573\/001\">T1573.001<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Symmetric Cryptography<\/td>\n<td width=\"265\">The Whisper backdoor makes use of AES encryption to ship and obtain knowledge between the malware and the C&amp;C.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1071\/001\">T1071.001<\/a><\/td>\n<td width=\"151\">Software Layer Protocol: Net Protocols<\/td>\n<td width=\"265\">PrimeCache makes use of customary net protocols for communication with the C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1132\/001\">T1132.001<\/a><\/td>\n<td width=\"151\">Knowledge Encoding: Customary Encoding<\/td>\n<td width=\"265\">PrimeCache makes use of customary encoding for communication with the C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1573\/002\">T1573.002<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Uneven Cryptography<\/td>\n<td width=\"265\">PrimeCache makes use of RSA and AES-CBC for C&amp;C communication.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1105\">T1105<\/a><\/td>\n<td width=\"151\">Ingress Instrument Switch<\/td>\n<td width=\"265\">PrimeCache has the aptitude to obtain further information from the C&amp;C server for native execution.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1048\/001\">T1048.001<\/a><\/td>\n<td width=\"151\">Exfiltration Over Various Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol<\/td>\n<td width=\"265\">The Whisper backdoor makes use of AES encryption and e mail inboxes to ship and obtain knowledge between the malware and the C&amp;C.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1041\">T1041<\/a><\/td>\n<td width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td width=\"265\">PrimeCache exfiltrates knowledge to a C&amp;C server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=bladedfeline-whispering-dark&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>In 2024, ESET researchers found a number of malicious instruments within the methods utilized by Kurdish and Iraqi authorities officers. The APT group behind the assaults is BladedFeline, an Iranian risk actor that has been lively since a minimum of 2017, when it compromised officers inside the Kurdistan Regional Authorities (KRG). This group develops malware [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3327,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3139,1092,3140],"class_list":["post-3325","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-bladedfeline","tag-dark","tag-whispering"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3325"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3325\/revisions"}],"predecessor-version":[{"id":3326,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3325\/revisions\/3326"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/3327"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-13 03:13:09 UTC -->