Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure
Unit 42 attributes Blinder Tunnel campaign to Iranian actors CL-STA-1178, targeting an Iraqi engineer via fake Dubai Airports coding test.
Palo Alto Networks Unit 42 identified the 'Blinder Tunnel' campaign, tracked as CL-STA-1178 and attributed with high confidence to an Iranian-nexus threat, activated in March 2026 against a likely Iraqi software engineer at critical-infrastructure-linked targets. Attackers impersonating Dubai Airports recruiters delivered a weaponized Visual Studio C# project that executed malicious code through project evaluation before the victim compiled anything. The chain used DLL sideloading of ShelbyLoader V2, AppDomainManager hijacking with ETW disabled, registry Run-key persistence, GitHub API command-and-control, in-memory PowerShell execution, and the Blackwood Chisel tunneling wrapper. Related credential-harvesting infrastructure targeted an Israeli entity in May-June 2026, and GitHub removed the identified attacker infrastructure.