Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2
Iranian-linked CL-STA-1178 posed as Dubai Airports recruiters to infect engineers with ShelbyLoader V2.
Unit 42 says Iranian state-aligned actor CL-STA-1178 impersonated Dubai Airports and sent software engineers a Visual Studio coding assessment. Opening the weaponized project abused MSBuild, AppDomainManager hijacking, and DLL sideloading to run ShelbyLoader V2 inside a renamed, Microsoft-signed host. The loader beaconed through a GitHub repository, decrypted ShelbyC2 in memory, and a Blackwood loader reflectively ran Chisel for tunneling. Researchers reported no compromise of Dubai Airports, and GitHub removed the infrastructure; related Blinder Tunnel activity has targeted Iraqi critical infrastructure since March 2026.
- Fake Dubai Airports Visual Studio test launched malware before compilation.
- Weaponized project abused MSBuild targets and AppDomainManager hijacking.
- DLL sideloading ran ShelbyLoader inside a signed Visual Studio host.
- GitHub repo peakyblinders-tm/myLic provided command and control.
- Unit 42 found no compromise of Dubai Airports systems.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 | 42fe3ec0244a372a410fc9 RuntimeBroker.dll Primary RAT loader 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 Note: IP addresses and domains are intentionally defanged ( |
| sha256 | 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 | DubaiAirport_Carrers_IT_Test.zip Initial malicious archive 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 FlightManager.csproj Weaponized Visual Studio project file |
| sha256 | f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 | FlightManager.csproj Weaponized Visual Studio project file f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 RuntimeBroker.dll Primary RAT loader 53f35e49eb9b271fd8cbcd |
Full article657 words · extracted from gbhackers.com · click to collapse
An Iranian state-aligned threat actor impersonated Dubai Airports recruiters to deliver weaponized coding assessments to software engineers.
The operation deployed ShelbyLoader V2 through a stealthy execution chain that abused legitimate Microsoft development tools and GitHub infrastructure.
Tracked as CL-STA-1178, the activity includes “Blinder Tunnel,” a campaign targeting Iraqi critical infrastructure beginning in March 2026.
The attackers initially distributed an Inno Setup installer named Dubai Airport Careers, which installed an offline recruitment portal.
Candidates received login credentials and completed a ten-question HR questionnaire.
This first application performed no observed exfiltration, network communication, or malicious execution.
Instead, it served as a credibility-building decoy before the attackers introduced the actual infection mechanism.
In April 2026, researchers identified DubaiAirport_Carrers_IT_Test.zip, a Visual Studio project archive presented as a recruitment assessment.
Its personalized Readme.md instructed the recipient to open a C# Flight Management System project, locate an intentionally flawed loop, and fix the bug.
The trap did not require completing the exercise. Opening the project could trigger malware execution before compilation.
The malicious .csproj file overrode the GetFrameworkPaths target invoked during Visual Studio background initialization. Its instructions copied concealed binaries into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launched RuntimeBroker.exe.
Unit42 Researchers assesses that, the Iranian nexus with high confidence, while emphasizing that it found no evidence of any compromise of Dubai Airports’ systems.

Microsoft’s MSBuild documentation describes the customizable targets and tasks underlying this abuse.
RuntimeBroker.exe was actually a renamed, Microsoft-signed Visual Studio hosting executable.
ShelbyLoader V2 Malware
An accompanying configuration file redirected its startup behavior through AppDomainManager hijacking, a technique that forces trusted .NET applications to load attacker-controlled assemblies.

The configuration also included <etwEnable enabled="false"/>, potentially impairing .NET Event Tracing for Windows visibility.
DLL sideloading completed the chain by loading RuntimeBroker.dll, identified as ShelbyLoader V2, into the trusted process.
ShelbyLoader V2 fingerprinted infected hosts, checked for virtualization artifacts, and established persistence through a MicrosoftRuntime registry startup value.
Security teams can detect this masquerading activity by monitoring abnormal process behavior. Cortex XDR flagged this execution chain as high risk and blocked the threat.
Its persistence routine ran every 120 seconds, while its primary beacon operated every 63 seconds.
Using an embedded personal access token, the loader communicated with the peakyblinders-tm/myLic GitHub repository, uploading host identifiers and polling files for commands.

If authentication failed, it searched GitHub issues for encrypted instructions concealed inside HTML comments.
This fallback could supply replacement repository details and credentials.
The architecture extends the GitHub-based command-and-control documented in Elastic Security Labs’ The Shelby Strategy, which analyzed earlier SHELBY malware targeting an Iraqi telecommunications organization.
The loader decrypted ShelbyC2 V2 directly into memory. Its PsProxy.dll module executed PowerShell through System.Management.Automation.dll without launching PowerShell.exe.
A separate Blackwood loader reflectively loaded Chisel, enabling encrypted tunnels and reverse SOCKS access for internal-network pivoting.
Researchers connected the campaign to credential-harvesting activity against an Israeli entity in May–June 2026.
Attribution relied on infrastructure overlaps, Iranian hosting, regional targeting, and Iranian music-site metadata embedded in a Peaky Blinders-themed audio file.
GitHub removed the identified malicious infrastructure. Defenders should investigate unexpected DLL loads, altered .NET configuration files.
Developer-tool processes launching executables from user-writable directories, while correlating those events with unusual GitHub API traffic and registry startup changes across affected developer endpoints.
IOCs
| File name | Description | SHA-256 |
|---|---|---|
DubaiAirport_Carrers_IT_Test.zip | Initial malicious archive | 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 |
FlightManager.csproj | Weaponized Visual Studio project file | f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 |
RuntimeBroker.dll | Primary RAT loader | 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.