DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data
DarkBlinders used a fake StarkMeet app and GitHub to backdoor systems and steal Kurdistan government data.
Dream researchers documented a DarkBlinders espionage campaign from August to October 2026 that used StarkMeet, a fake meeting application, against targets in Israel and the Kurdistan Region of Iraq. The unsigned installer plants a loader that persists through a Windows Run key, registers hosts in a GitHub repository, and selectively decrypts an in-memory backdoor that executes PowerShell without powershell.exe. Confirmed impact included credential theft and exfiltration of at least 1 GB from a Kurdistan government cloud environment, plus compromise of an Israeli security-sector individual. Phishing pages also impersonated Kuwait’s foreign ministry and the Gulf Cooperation Council. Dream reported medium-to-high confidence overlap with UNC5795 and Dust Specter, and medium-confidence links to UNC5187 and possibly APT34.
- Fake StarkMeet installer hides a persistent RuntimeBroker loader.
- GitHub repositories handle host registration, tasking, and backup tokens.
- The backdoor runs PowerShell in memory without launching powershell.exe.
- Operators stole at least 1 GB from a Kurdistan government cloud.
- Dream assessed medium-to-high overlap with UNC5795 and Dust Specter.
Full article492 words · extracted from gbhackers.com · click to collapse
DarkBlinders hackers are deploying a fake video meeting application and abusing GitHub repositories in a cyberespionage campaign targeting Israel and the Kurdistan Region of Iraq.
Dream researchers observed the operation between August and October 2026. The investigation confirmed compromises affecting a government cloud environment in Kurdistan and a prominent Israeli individual associated with the security sector.
DarkBlinders Hackers Use Fake Meeting App
Recovered operator tasking revealed credential theft and the exfiltration of at least 1 GB of government cloud data, providing direct visibility into the campaign’s impact.
The operation combines government webmail impersonation, fraudulent cloud sharing pages, and StarkMeet, a decoy meeting client. Phishing infrastructure mimicked Kuwait’s Ministry of Foreign Affairs and the Gulf Cooperation Council Secretariat General, indicating interest in diplomatic targets beyond the two confirmed victims.

StarkMeet’s unsigned Inno Setup installer presents version 3.2 of an apparently legitimate application. Camera, microphone, and screen previews work locally, but joining a meeting always generates a fixed connection error.
Researchers did not recover the original delivery message, leaving the initial distribution route unconfirmed. Meanwhile, the installer places malicious components under %LOCALAPPDATA%\Microsoft\RuntimeBroker, separately from the visible application.
This arrangement allows the malware to survive removal of StarkMeet. A signed Microsoft vshost.exe, renamed RuntimeBroker.exe, loads RuntimeBroker.dll through an AppDomainManager mechanism.
The MicrosoftRuntime value in the current user’s Windows Run registry key establishes persistence. The loader uses an embedded GitHub token to register infected systems in the PeakyBlindersTeam/myLic repository.
Reports contain usernames, machine names, domains, keyboard layouts, persistence status, and anti-analysis findings, allowing operators to evaluate targets before activating the next stage.
Dreamgroup identified approximately ten initial host registrations but only two victims in the second-stage tasking repository. This discrepancy supports selective activation rather than automatic deployment.

For chosen systems, operators supply license material whose SHA-256 hash becomes the AES-256-CBC key used to decrypt RuntimeBrokerApi.dll. The decrypted assembly loads directly into memory.
The backdoor polls the separate myCode repository approximately every 63 seconds. Its embedded PsProxy.dll helper executes PowerShell through an internal runspace without launching powershell.exe, reducing visibility for detections dependent on that child process. Additional functions support file uploads, downloads, and ZIP extraction.
Both stages can recover replacement GitHub credentials from specially formatted comments in public Microsoft/vscode issues, potentially restoring communications after token revocation.
Dream linked the operation to four earlier campaign waves and assessed medium-to-high confidence overlap with UNC5795 and Dust Specter.
Relationships with UNC5187 and possible placement within APT34 carry medium confidence. Persian keyboard metadata and Iranian hosting associations provide context, but neither independently establishes attribution or identifies operators.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.