Blinder Tunnel Campaign Targets Iraqi Infrastructure
Unit 42 attributes the Blinder Tunnel campaign to Iranian state-aligned CL-STA-1178, which impersonated Dubai Airports IT to hit Iraqi critical infrastructure.
Unit 42 tracks an Iranian state-aligned threat actor, CL-STA-1178, running the Blinder Tunnel campaign against Iraqi critical infrastructure from March 2026, with infrastructure staged since November 2025. The actor used fake Dubai Airports recruitment lures delivering trojanized coding challenges, then a three-step chain: weaponized .csproj files, AppDomainManager hijacking, and DLL sideloading to deploy ShelbyLoader V2 malware. C2 abused GitHub API repositories for decryption keys, payload delivery, and GitHub issues as fallback. OpSec errors linked the campaign to Google Drive credential harvesting against an Israeli entity in May-June 2026; GitHub has taken down the malicious infrastructure.