DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data
DarkBlinders used a fake StarkMeet app and GitHub to backdoor systems and steal Kurdistan government data.
Dream researchers documented a DarkBlinders espionage campaign from August to October 2026 that used StarkMeet, a fake meeting application, against targets in Israel and the Kurdistan Region of Iraq. The unsigned installer plants a loader that persists through a Windows Run key, registers hosts in a GitHub repository, and selectively decrypts an in-memory backdoor that executes PowerShell without powershell.exe. Confirmed impact included credential theft and exfiltration of at least 1 GB from a Kurdistan government cloud environment, plus compromise of an Israeli security-sector individual. Phishing pages also impersonated Kuwait’s foreign ministry and the Gulf Cooperation Council. Dream reported medium-to-high confidence overlap with UNC5795 and Dust Specter, and medium-confidence links to UNC5187 and possibly APT34.