PrimeCache is a malicious 64-bit native IIS module backdoor implemented as a DLL named cachehttp.dll with an internal name of HttpModule.dll. It functions as a passive backdoor by monitoring incoming HTTP requests for attacker commands, specifically requests matching a predefined cookie header structure such as F=<command_ID>,<param>;. Reported capabilities include command execution, file creation, and file exfiltration. Its command-and-control communications use RSA and AES-CBC encryption. PrimeCache has been associated with the Iran-aligned threat group BladedFeline and was observed in campaigns targeting Kurdish and Iraqi government officials, Kurdistan Regional Government environments, and a regional telecommunications provider in Uzbekistan as part of long-term cyberespionage activity. ESET assessed with medium confidence that BladedFeline is a subgroup of OilRig, and PrimeCache reportedly shares code similarities with OilRig’s RDAT backdoor, including use of Crypto++ and a shared shell-command execution function.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PrimeCache also serves as a backdoor: it is a malicious IIS module related to what we referred to as Group 2 in our 2021 paper Anatomy of native IIS malware.
PrimeCache also serves as a backdoor: it is a malicious IIS module related to what we referred to as Group 2 in our 2021 paper Anatomy of native IIS malware.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
PrimeCache uses standard web protocols for communication with the C&C server.
PrimeCache action... u AES-encrypted file content Local filename Creates a local file with the specified name and content... In the case where we do not have a location on disk for Laret... Laret was downloaded from http://178.209.51[.]61:8000/wincapsrv.exe via PowerShell.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious IIS module used for stealthy persistence and command retrieval by monitoring HTTP requests for attacker commands.
Backdoor module for Internet Information Services (IIS), used for cyberespionage and data exfiltration, with code similarities to the RDAT backdoor used by OilRig.
Passive backdoor implemented as a malicious IIS module; triggers on HTTP requests with a specific cookie header structure to process attacker commands and exfiltrate files.
A passive malicious native IIS module backdoor that filters HTTP requests for operator cookies, caches parameters across requests, executes commands, uploads/downloads files, and uses RSA plus AES-CBC for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.