Unit 42 has identified a targeted cyber campaign, dubbed Blinder Tunnel, orchestrated by an Iranian state-aligned threat actor tracked as CL-STA-1178. This operation, active since at least March 2026, focuses on critical infrastructure entities in Iraq, with related activities observed against targets in Israel and the United Arab Emirates. The campaign employs a sophisticated social engineering scheme, impersonating the Dubai Airports IT department to lure software engineers with fake job opportunities.
The primary payload is a custom malware family named ShelbyLoader V2, delivered through a multi-stage infection process that leverages emerging evasion techniques like AppDomainManager hijacking. A key feature of this campaign is its abuse of the GitHub API for command-and-control (C2) communications, allowing malicious traffic to blend in with legitimate network activity. The actor's infrastructure and malware exhibit a thematic connection to the TV show "Peaky Blinders." Despite the actor's sophistication, operational security errors allowed researchers to link this campaign to other regional operations, providing a broader view of this threat actor's activities.
The Blinder Tunnel campaign represents a significant evolution in the tactics of the Iranian-nexus threat actor CL-STA-1178, previously associated with activity tracked as "The Shelby Strategy." The campaign's primary objective appears to be establishing long-term, covert access to high-value targets within the telecommunications, aviation, and other critical infrastructure sectors across the Middle East.
The initial attack vector is a highly targeted social engineering attack. The threat actor impersonates recruiters from Dubai Airports and approaches specific individuals, likely software engineers, with a tailored job offer. The target is instructed to download and execute an installer for a supposed coding assessment, which is in fact the first stage of the malware infection. This installer, Dubai Airport Careers, deploys a fake career portal to maintain the pretext of a legitimate recruitment process while covertly initiating the attack chain.
The infection chain is a multi-step process designed for stealth and evasion:
Initial Access: The target receives a file named Dubai Airport Careers, an Inno Setup installer. This is delivered via a social engineering lure. This corresponds to T1566.001 - Spearphishing Attachment.
Execution & Evasion: The installer deploys a fake offline career portal. Upon user interaction, it triggers the execution of a malicious .csproj file. This leverages a trusted Microsoft developer file type to evade initial detection. This action leads to AppDomainManager hijacking, a technique where a trusted Windows application is forced to load and execute a malicious payload in memory. This is followed by DLL sideloading to establish persistence and further execution. This activity maps to T1195.001 - Compromise Software Dependencies and Development Tools and T1574.002 - DLL Side-Loading.
Payload Deployment: The evasion techniques are used to load and execute the primary payload, ShelbyLoader V2, a custom malware designed for espionage and remote access.
Command and Control (C2): The Blinder Tunnel campaign utilizes a "living off the cloud" strategy by misusing the legitimate GitHub API for C2 communications (T1071.001 - Web Protocols). This makes it difficult for network defenders to distinguish malicious traffic from legitimate developer activity. The GitHub repository also hosted an in-memory wrapper for the open-source Chisel tunneling utility, which was used to bridge the compromised network with the attacker's external infrastructure (T1105 - Ingress Tool Transfer).
The Blinder Tunnel campaign poses a significant threat to critical infrastructure in the Middle East. By targeting software engineers and developers within these organizations, the attackers gain an initial foothold that can be leveraged for several malicious purposes:
While Dubai Airports was not breached, the impersonation of its brand damages its reputation and places its recruitment partners and potential candidates at risk. The targeting of individuals in Iraq, Israel, and the UAE indicates a broad regional focus for this threat actor. The primary business impact is the high risk of data exfiltration and the potential for operational disruption within compromised entities.
The source article did not provide specific Indicators of Compromise (IOCs) such as file hashes, IP addresses, or domains, noting that the malicious GitHub infrastructure had been taken down.
Security teams may want to hunt for the following patterns which could indicate related activity:
Dubai Airport Careers*.csprojChiselapi.github.commscoree.dllmscoree.dll, which can be an indicator of AppDomainManager hijacking.Detecting the Blinder Tunnel campaign requires a multi-layered approach focusing on behavior rather than static signatures.
.csproj files by non-standard parent processes. Monitor for known DLL sideloading patterns and the loading of mscoree.dll by unexpected applications. D3FEND's D3-PA - Process Analysis is a key technique here.D3-NTA - Network Traffic Analysis.If a compromise is suspected, the immediate response should be to isolate the affected endpoints, preserve forensic evidence, and initiate an incident response investigation to determine the full scope of the breach.
Defending against this threat requires both technical controls and security awareness.
M1017 - User Training..csproj files to only authorized developer tools can be an effective control. This relates to M1038 - Execution Prevention.M1030 - Network Segmentation.M1051 - Update Software.Train employees, especially those in high-value roles like software development, to recognize and report sophisticated social engineering and recruitment fraud.
Use application control solutions to restrict the execution of unauthorized installers and scripts. Specifically, block the execution of .csproj files outside of approved developer environments.
Filter and monitor outbound web traffic. While blocking GitHub may be impractical, proxying and inspecting traffic can help identify anomalous C2 communications.
Implement egress filtering to block outbound connections from servers and workstations to non-essential destinations, disrupting potential C2 channels.
Mapped D3FEND Techniques:
Use modern EDR and antivirus solutions that employ behavioral analysis to detect suspicious process chains, DLL sideloading, and in-memory execution.
Mapped D3FEND Techniques:
To counter the Blinder Tunnel campaign's TTPs, organizations should implement advanced process analysis using an Endpoint Detection and Response (EDR) solution. This goes beyond simple signature-based detection. Configure EDR to monitor for anomalous process chains, specifically the execution of .csproj files by any process other than devenv.exe or other sanctioned developer tools. Create high-fidelity alerts for when a non-standard process (e.g., from an Inno Setup installer) spawns a process that loads the .NET runtime and begins compiling or executing a C# project. Furthermore, process analysis should be used to baseline normal DLL loading behavior for trusted applications. An alert should be triggered if a trusted system process is observed loading DLLs from non-standard directories, a key indicator of the DLL sideloading technique used by this actor. This technique is critical for detecting the initial execution and evasion stages of the Blinder Tunnel attack chain before the main payload is deployed.
Given the actor's use of the GitHub API for command and control, Network Traffic Analysis (NTA) is a crucial defensive measure. Organizations should deploy NTA tools or leverage SIEM capabilities to analyze NetFlow, proxy logs, and firewall logs. The goal is to establish a baseline of normal GitHub traffic within the environment. Detections should focus on identifying outliers from this baseline. For instance, a server in a production DMZ that has never communicated with api.github.com suddenly starting to do so would be a high-priority alert. Analyze the metadata of TLS connections to GitHub, looking for non-standard user agents or periodic, 'heartbeat'-like connections characteristic of C2 traffic. Correlate network data with endpoint process data; if a process that is not git.exe or a known developer tool is making sustained connections to GitHub, it warrants immediate investigation. This technique directly addresses the actor's 'living off the cloud' strategy by making it harder for their C2 traffic to hide in plain sight.
Implementing executable allowlisting provides a robust defense against the initial stages of the Blinder Tunnel attack. By defining a strict policy of what software is permitted to run, organizations can prevent the execution of the unauthorized Dubai Airport Careers Inno Setup installer. This should be deployed in 'enforce' mode on critical servers and for privileged user groups. For developer workstations, where more flexibility is needed, a more tailored policy can be created. For example, allow the execution of .csproj files only when initiated by a code-signed instance of Visual Studio (devenv.exe). This prevents the exact evasion technique used in this campaign, where a legitimate file type is abused by a malicious loader. While implementing a comprehensive allowlisting policy requires significant initial effort in baselining and policy tuning, it is one of the most effective ways to break this and many other attack chains at the execution stage.
Threat actor begins staging and testing attack infrastructure for the Blinder Tunnel campaign.
The Blinder Tunnel campaign is activated, targeting an individual within Iraq's critical infrastructure sector.
A separate but related campaign is launched by the same actor against an Israeli entity using Google Drive lures.
Unit 42 publishes its research on the Blinder Tunnel campaign.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.