Shahmaran is a simple 64-bit PE backdoor used by the Iran-aligned threat group BladedFeline, which ESET assesses with medium confidence to be a sub-cluster of OilRig. ESET reported discovering the group in 2023 after attacks targeting Kurdish diplomatic officials with Shahmaran. The malware has been used in cyberespionage operations against Kurdish and Iraqi government officials, including victims associated with the Kurdistan Regional Government (KRG), and is part of a broader BladedFeline toolkit used to maintain and expand access in Iraq and neighboring regional targets.
Shahmaran was found in the Startup folder as adobeupdater.exe. It checks in with a remote server every 30 seconds and executes operator-provided commands. Reported capabilities include remote code execution, file upload and download, requesting file attributes, and file and directory manipulation. Network communications are not encrypted or compressed. The backdoor uses the hardcoded command-and-control domain olinpa[.]com over port 80.
High-confidence indicators and characteristics directly mentioned in the reporting include the filename adobeupdater.exe, placement in the Startup folder, and the C2 domain olinpa[.]com:80. Shahmaran is consistently described as a backdoor associated with BladedFeline’s long-term espionage activity against Kurdish diplomatic officials and Iraqi government-related targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We discovered the group in 2023 when it deployed its Shahmaran backdoor against Kurdish diplomatic officials.
BladedFeline is known to employ a diverse malware toolkit, including backdoors like Shahmaran, Whisper, Spearal, and Optimizer, each offering remote code execution (RCE) and data exfiltration capabilities.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The Shahmaran backdoor... was found in the startup folder as: %ROAMINGAPPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\adobeupdater.exe ... Whisper Protocol also copies itself to %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VeeamUpdate.lnk for persistence.
The Shahmaran backdoor... was found in the startup folder as: %ROAMINGAPPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\adobeupdater.exe ... Whisper Protocol also copies itself to %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VeeamUpdate.lnk for persistence.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by BladedFeline providing remote code execution and data exfiltration.
Simple backdoor used for remote command execution and basic file operations (upload/download, file attribute requests, file/directory manipulation) via check-ins to a remote server.
A 64-bit backdoor that communicates with a hardcoded C2 over HTTP, executes operator commands, supports file and directory manipulation, and does not use compression or encryption for network communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.