Hawking Listener
Hawking Listener is an early-stage 32-bit .NET/C# Windows implant that uses the .NET HTTPListener class to open a listener on a specified port and execute commands through cmd.exe. Reporting links it to the Iran-aligned threat group BladedFeline, which ESET assesses with medium confidence to be a subgroup of OilRig. The malware has been described as part of BladedFeline’s broader toolset used in long-term cyberespionage operations against Kurdish and Iraqi government officials, including Kurdistan Regional Government environments, and it has also been mentioned alongside activity affecting a regional telecommunications provider in Uzbekistan. Hawking Listener receives commands via HTTP, including through a specific QueryString key, and functions as a supplementary implant within a larger intrusion set that also includes tools such as Slippery Snakelet, Laret, Pinar, Whisper, Shahmaran, PrimeCache, and Flog. A Hawking Listener sample was reported uploaded to VirusTotal in March 2024 by the same submitter associated with the Flog web shell.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hawking Listener, so named for its PDB string ... is a 32-bit .NET/C# Windows binary ... It implements the .NET HTTPListener class to set up a listener.
The threat group has also deployed newer implants like Slippery Snakelet and Hawking Listener, as well as tunneling tools Laret and Pinar for persistence.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Stealth
1 technique
Stealth
Both have timestomped PE compilation timestamps – a tactic that is common amongst Middle Eastern (and particularly Iran-nexus) threat groups... Both these versions of Whisper have timestomped compilation timestamps... BladedFeline routinely timestomps the compilation timestamps of malware that the group develops.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer implant attributed to BladedFeline; used for persistent access (exact capabilities not detailed in the content).
Early-stage implant that listens on a specified port and enables command execution via cmd.exe.
A .NET implant that opens an HTTP listener, executes commands received via a specific query-string key, returns command output, and logs activity locally.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.