Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2
Iranian-linked CL-STA-1178 posed as Dubai Airports recruiters to infect engineers with ShelbyLoader V2.
Unit 42 says Iranian state-aligned actor CL-STA-1178 impersonated Dubai Airports and sent software engineers a Visual Studio coding assessment. Opening the weaponized project abused MSBuild, AppDomainManager hijacking, and DLL sideloading to run ShelbyLoader V2 inside a renamed, Microsoft-signed host. The loader beaconed through a GitHub repository, decrypted ShelbyC2 in memory, and a Blackwood loader reflectively ran Chisel for tunneling. Researchers reported no compromise of Dubai Airports, and GitHub removed the infrastructure; related Blinder Tunnel activity has targeted Iraqi critical infrastructure since March 2026.