Slippery Snakelet is a small Python-based backdoor used by the Iran-aligned threat group BladedFeline, which ESET assesses with medium confidence to be a subgroup or sub-cluster of OilRig (APT34/Hazel Sandstorm). It was reported in attacks observed in late 2023 and early 2024 targeting Kurdish and Iraqi government officials, including entities within the Kurdistan Regional Government (KRG), and was also mentioned as part of a broader BladedFeline toolset used in long-term cyberespionage operations affecting Iraq and related regional targets. The malware has limited capabilities: it can execute commands via cmd.exe, download files from a URL, and upload files, including to the /newfile/ URI path. Supporting reporting states it uses the hardcoded C2 domain zaincell[.]store and disguises the server as an Arabian Gulf E-Learning site. It has been deployed alongside other BladedFeline implants and access tools including Shahmaran, Whisper, Hawking Listener, and the Laret and Pinar tunneling tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Slippery Snakelet is a small Python-based backdoor with limited capabilities: 1. executes a command via cmd.exe, 2. downloads a file from a URL, and 3. upload a file to the /newfile/ URI path.
The threat group has also deployed newer implants like Slippery Snakelet and Hawking Listener, as well as tunneling tools Laret and Pinar for persistence.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer implant attributed to BladedFeline; used for persistent access (exact capabilities not detailed in the content).
Python implant with limited functionality: execute commands via cmd.exe, download files from external URLs, and upload files.
A lightweight Python backdoor with command execution, file download, and file upload capabilities that communicates with a hardcoded HTTPS C2 using encoded victim identifiers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.