Blinder Tunnel: Iranian-Linked CL-STA-1178 Targets Iraqi Critical Infrastructure via Fake Dubai Airports Coding Tests
Unit 42 attributes the Blinder Tunnel campaign to Iranian state-aligned CL-STA-1178, which impersonated Dubai Airports recruiters and used weaponized Visual Studio projects to deploy ShelbyLoader V2 against Iraqi critical infrastructure.
Palo Alto Networks Unit 42 attributes the Blinder Tunnel campaign, tracked as CL-STA-1178, with high confidence to an Iranian state-aligned threat actor. The campaign was activated in March 2026 against a likely Iraqi software engineer linked to critical infrastructure, with attacker infrastructure staged since November 2025; Unit 42 names Iraq, Israel, and the UAE as targets, while the GBHackers account centers on Iraq and does not describe UAE targeting. Impersonating Dubai Airports recruiters, the actor delivered trojanized Visual Studio coding assessments in which malicious code executed through project evaluation before the victim compiled anything. The execution chain abused MSBuild via weaponized .csproj files, AppDomainManager hijacking with ETW disabled, and DLL sideloading to run ShelbyLoader V2 inside a renamed, Microsoft-signed Visual Studio host. The loader used the GitHub API for decryption keys and payload delivery and beaconed through the repository peakyblinders-tm/myLic, with GitHub issues as a fallback C2 channel. It decrypted ShelbyC2 in memory, and a Blackwood loader reflectively ran Chisel for tunneling; Cyber Security News additionally reports registry Run-key persistence and in-memory PowerShell execution. Unit 42 says operational-security errors linked the actor to Google Drive credential harvesting against an Israeli entity in May-June 2026, and Peaky Blinders-themed branding ties the activity to prior campaigns. Researchers reported no compromise of Dubai Airports, and GitHub has taken down the malicious infrastructure.
- Attributed with high confidence to Iranian state-aligned threat actor CL-STA-1178 (Blinder Tunnel campaign)
- Campaign activated March 2026 against Iraqi critical infrastructure, with infrastructure staged since November 2025
- Victim described as a likely Iraqi software engineer at a critical-infrastructure-linked entity; Unit 42 lists targets in Iraq, Israel, and the UAE, while GBHackers centers on Iraq and omits UAE targeting
- Fake Dubai Airports recruiter lures delivered trojanized Visual Studio coding assessments that executed malicious code during project evaluation, before compilation
- Execution chain: weaponized .csproj files abusing MSBuild, AppDomainManager hijacking with ETW disabled, and DLL sideloading into a renamed, Microsoft-signed Visual Studio host
- ShelbyLoader V2 deployed; decrypted ShelbyC2 in memory; a Blackwood loader reflectively ran Chisel for tunneling
- GitHub API used for decryption keys, payload delivery, and C2 via repository peakyblinders-tm/myLic, with GitHub issues as fallback
- Cyber Security News additionally reports registry Run-key persistence and in-memory PowerShell execution
Coverage timelineoldest first · each row is one article
- · 2d agoBlinder Tunnel Campaign Targets Iraqi Infrastructure
Palo Alto Unit 42· 78
Unit 42 attributes the Blinder Tunnel campaign to Iranian state-aligned CL-STA-1178, which impersonated Dubai Airports IT to hit Iraqi critical infrastructure.
- · 2d agoHackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2
GBHackers· 74
Iranian-linked CL-STA-1178 posed as Dubai Airports recruiters to infect engineers with ShelbyLoader V2.
- · 2d agoIranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure
Cyber Security News· 73