newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Iran-linked blade ferine hits Iraqi and Kurdish targets with whispers and spear malware
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Iran-linked blade ferine hits Iraqi and Kurdish targets with whispers and spear malware
Technology

Iran-linked blade ferine hits Iraqi and Kurdish targets with whispers and spear malware

June 7, 2025 5 Min Read
Share
Iran-linked blade ferine hits Iraqi and Kurdish targets with whispers and spear malware
SHARE

The hacking groups lined up in Iran are attributed to a new set of cyberattacks targeting Kurdish and Iraqi government officials in early 2024.

Activities are associated with threat group ESET tracks Blade Ferrinrated with moderate confidence to become a subcluster within the oil rig, known cyber actors of Iranian nation-states. It is said to have been active since September 2017, when it targeted officials related to the Kurdistan Regional Government (KRG).

“The group is developing malware to maintain and expand access within Iraq and KRG organizations,” Slovak Cybersecurity Company said in a technical report shared with Hacker News.

“Bladeferin has consistently worked to maintain illegal access to Kurdish diplomats, while simultaneously using local telecommunications providers in Uzbekistan to develop and maintain access to Iraqi government officials.”

BladedFeline was first documented by ESET as part of its APT activity report in May 2024, detailing enemy attacks on government organisations from the Kurdistan region of Iraq and targeting Uzbekistan mail order companies that they compromised in May 2022.

The group was discovered in 2023 following an attack targeting Kurdish diplomats using Shahmaran, a simple backdoor that checks in on a remote server, runs commands provided by the operator of an infected host to upload or download files, request specific file attributes, and provides file and directory manipulation APIs.

Then last November, the cybersecurity company said it had observed attacks on Iranian neighbours, particularly hacking crews against Iraq’s regions and government agencies, as well as diplomatic missions from Iraq to various countries.

“Bladedfeline invests heavily in the collection of diplomatic and financial information from Iraqi organisations, indicating that Iraq plays a major role in the Iranian government’s strategic goals,” ESET said in November 2024.

See also  AI Control Dilemma: Risks and Solutions

The exact initial access vector used to enter the victims of KRG is unknown, but it is suspected that threat actors will likely leverage vulnerabilities in their internet-oriented applications to infiltrate Iraqi government networks and deploy a frog webshell to maintain permanent remote access.

How the Whisperback Door works

The wide range of backdoors highlight Bladeferrin’s commitment to refine the malware Arsenal. Whisper logs in to a compromised webmail account on Microsoft Exchange Server and communicates with the attacker via email attachments, C#/. It’s a net back door. Spearal is a .NET backdoor that uses DNS tunnels for command and control communications.

“The optimizer is a repetitive update of the spear backdoor. It uses the same workflow and offers the same functionality. The main difference between the spear and the optimizer is mainly cosmetics,” an ESET research team told Hacker News.

Some attacks observed in December 2023 also include the deployment of a Python implant called a slippery snikelet with limited functionality to execute commands via “cmd.exe”.

Despite the backdoor, BladedFeline is noteworthy for using various tunneling tools Laret and Pinar to maintain access to the target network. We also use a malicious IIS module called Primecache. ESET said there is similarity to the RDAT backdoor used by OilRig Apt.

A passive backdoor, Primecache works by focusing on contained HTTP requests that match predefined cookie header structures to process commands issued by attackers and issued by files.

This aspect, coupled with the fact that OilRig’s two tools (RDAT and Reverse Shell CodeNayed VideoSRV) were discovered in the KRG systems that we compromised in September 2017 and September 2018, respectively, suggests that BladedFeLine may be a subgroup within Oilrig, but it differs from the range of subusters in Lyceum-subruster.

See also  Google publishes vishing group UNC6040 targeting salesforce with fake data loader app

Additionally, oil rig connections have been strengthened with reports from the September 2024 checkpoint. This led to infiltrating a network of Iraqi government networks and pointing fingers at Iranian hacking groups to infect whispers and spears using the possibilities of social engineering.

ESET said it had identified a malicious artifact named Hawking Listener that was uploaded to the Baltotal platform by the same party that uploaded the Frog in March 2024. The Hawking Listener runs the command via “cmd.exe” with an early stage implant that listens to the specified port.

“Bladedfeline targets KRG and GOI for cyberspy purposes and is looking to maintain strategic access to senior officials from both government agencies,” the company concluded.

“KRG’s diplomatic ties with Western countries, coupled with oil reserves in the Kurdistan region, have become an attractive target for Iranian-aligned threat actors to spy on and potentially manipulate.

Share This Article
Facebook Twitter Copy Link
Previous Article Merab Dvalishvili breaks silence with toe injuries that cast serious doubt in the UFC 316 showdown with Sean O’Malley Merab Dvalishvili breaks silence with toe injuries that cast serious doubt in the UFC 316 showdown with Sean O’Malley
Next Article Cannes Un Certain Regard jury prize winner ‘A Poet’ lands US deal Cannes Un Certain Regard jury prize winner ‘A Poet’ lands US deal
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

How AI agents are transforming the education sector: See Kira Learning and Beyond
Technology

How AI agents are transforming the education sector: See Kira Learning and Beyond

11 Min Read
New Pathwiper Data Wiper Malware Destroys Ukraine’s Critical Infrastructure in 2025 Attack
Technology

New Pathwiper Data Wiper Malware Destroys Ukraine’s Critical Infrastructure in 2025 Attack

9 Min Read
US DOJ seizes four domains that support cybercrime crypto services in global operations
Technology

US DOJ seizes four domains that support cybercrime crypto services in global operations

4 Min Read
Fake recruiters email target CFOs using legal netbird tools in six global regions
Technology

Fake recruiters email target CFOs using legal netbird tools in six global regions

9 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?