Pinar is a 32-bit .NET reverse tunneling tool used by the Iran-aligned threat group BladedFeline, which ESET assesses with medium confidence to be a subgroup or sub-cluster of OilRig (APT34/Hazel Sandstorm). It has been used in long-term cyberespionage operations targeting Kurdish and Iraqi government officials, Kurdistan Regional Government environments, and related regional targets; reporting also links the broader BladedFeline campaign to a regional telecommunications provider in Uzbekistan. Pinar is described as an SSH-based port-forwarding implant that relies on an external configuration file for command-and-control parameters and is used to maintain access to compromised networks. Unlike Laret, the related reverse tunnel, Pinar includes built-in persistence by creating a Windows service named Service1. In the reported intrusions, Pinar was part of a broader toolset that included backdoors such as Whisper and Shahmaran, the PrimeCache malicious IIS module, and other supplementary implants used to sustain covert access and support espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We analyze two reverse tunnels (Laret and Pinar), a backdoor (Whisper), a malicious IIS module (PrimeCache), and various supplementary tools.
The threat group has also deployed newer implants like Slippery Snakelet and Hawking Listener, as well as tunneling tools Laret and Pinar for persistence.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Both have timestomped PE compilation timestamps – a tactic that is common amongst Middle Eastern (and particularly Iran-nexus) threat groups... Both these versions of Whisper have timestomped compilation timestamps... BladedFeline routinely timestomps the compilation timestamps of malware that the group develops.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling tool used by BladedFeline to support persistence (exact protocol/implementation not detailed in the content).
Tunneling tool used to maintain access to target networks.
A 32-bit .NET reverse tunnel similar to Laret that uses SSH-based port forwarding and additionally installs itself as a Windows service for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.