Whisper, also known as Veaty, is a C#/.NET backdoor used in cyberespionage operations attributed to the Iran-aligned BladedFeline cluster, which has been assessed with medium confidence as a subgroup of OilRig. It has been observed targeting Kurdish and Iraqi government officials and related regional entities, including a telecommunications provider in Uzbekistan, as part of long-term intelligence collection and access-maintenance campaigns.
Whisper operates by authenticating to a compromised Microsoft Exchange webmail account and using that mailbox as a covert command-and-control channel. It communicates with operators through email attachments rather than direct network beacons to a conventional command server. Reported functionality includes periodic check-ins, decryption and execution of operator tasking, file write operations, file exfiltration, and execution of PowerShell commands, giving operators remote code execution and data theft capability on infected Windows hosts.
Documented tradecraft includes creation or verification of an Exchange inbox rule to filter operator traffic and use of encrypted command content delivered through the compromised mail account. In observed campaigns, Whisper was deployed after an undetermined initial access phase and then used to sustain espionage activity against government and diplomatic targets. Its use of legitimate enterprise messaging infrastructure for command transport aligns with broader OilRig-associated patterns of blending malicious traffic into normal business services and reducing detection opportunities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...while Whisper/Veaty malware used compromised Iraqi government Microsoft 365 mailboxes.
Whisper is a backdoor that logs into a compromised webmail account on a Microsoft Exchange server and uses it to communicate with the attackers via email attachments.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Eset first observed it in 2023, when it planted a backdoor into systems used by government diplomats from the Kurdistan Regional Government.
Both have timestomped PE compilation timestamps – a tactic that is common amongst Middle Eastern (and particularly Iran-nexus) threat groups... Both these versions of Whisper have timestomped compilation timestamps... BladedFeline routinely timestomps the compilation timestamps of malware that the group develops.
BladedFeline used a backdoor its dubs Whisper which, when planted inside a target device, logged into a compromised webmail account on a Microsoft Exchange server and used it to communicate with the attackers through email attachments.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as prior OilRig tooling that used compromised Microsoft 365 mailboxes for operations.
Named backdoor listed among malware/tools, without substantive discussion in this reference.
Malware referenced as using compromised Microsoft 365 mailboxes as part of its operations.
Backdoor used in targeted intrusions against Kurdish and Iraqi government officials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.