Blinder Tunnel Campaign Targets Iraqi Critical Infrastructure

Iranian Actor Targets Iraqi Infrastructure with "Blinder Tunnel"

HIGH
October 6, 2026
7m read
Threat ActorMalwareCyberattack

Related Entities

Threat Actors

CL-STA-1178IranScreening Serpens

Organizations

Unit 42 Palo Alto Networks Elastic Security Labs

Products & Tech

GitHub ChiselCortex AgentiXVirusTotal Google Drive

Other

Dubai Airports ShelbyLoader V2

Full Report

Executive Summary

Unit 42 has identified a targeted cyber campaign, dubbed Blinder Tunnel, orchestrated by an Iranian state-aligned threat actor tracked as CL-STA-1178. This operation, active since at least March 2026, focuses on critical infrastructure entities in Iraq, with related activities observed against targets in Israel and the United Arab Emirates. The campaign employs a sophisticated social engineering scheme, impersonating the Dubai Airports IT department to lure software engineers with fake job opportunities.

The primary payload is a custom malware family named ShelbyLoader V2, delivered through a multi-stage infection process that leverages emerging evasion techniques like AppDomainManager hijacking. A key feature of this campaign is its abuse of the GitHub API for command-and-control (C2) communications, allowing malicious traffic to blend in with legitimate network activity. The actor's infrastructure and malware exhibit a thematic connection to the TV show "Peaky Blinders." Despite the actor's sophistication, operational security errors allowed researchers to link this campaign to other regional operations, providing a broader view of this threat actor's activities.

Threat Overview

The Blinder Tunnel campaign represents a significant evolution in the tactics of the Iranian-nexus threat actor CL-STA-1178, previously associated with activity tracked as "The Shelby Strategy." The campaign's primary objective appears to be establishing long-term, covert access to high-value targets within the telecommunications, aviation, and other critical infrastructure sectors across the Middle East.

The initial attack vector is a highly targeted social engineering attack. The threat actor impersonates recruiters from Dubai Airports and approaches specific individuals, likely software engineers, with a tailored job offer. The target is instructed to download and execute an installer for a supposed coding assessment, which is in fact the first stage of the malware infection. This installer, Dubai Airport Careers, deploys a fake career portal to maintain the pretext of a legitimate recruitment process while covertly initiating the attack chain.

Technical Analysis

The infection chain is a multi-step process designed for stealth and evasion:

  1. Initial Access: The target receives a file named Dubai Airport Careers, an Inno Setup installer. This is delivered via a social engineering lure. This corresponds to T1566.001 - Spearphishing Attachment.

  2. Execution & Evasion: The installer deploys a fake offline career portal. Upon user interaction, it triggers the execution of a malicious .csproj file. This leverages a trusted Microsoft developer file type to evade initial detection. This action leads to AppDomainManager hijacking, a technique where a trusted Windows application is forced to load and execute a malicious payload in memory. This is followed by DLL sideloading to establish persistence and further execution. This activity maps to T1195.001 - Compromise Software Dependencies and Development Tools and T1574.002 - DLL Side-Loading.

  3. Payload Deployment: The evasion techniques are used to load and execute the primary payload, ShelbyLoader V2, a custom malware designed for espionage and remote access.

  4. Command and Control (C2): The Blinder Tunnel campaign utilizes a "living off the cloud" strategy by misusing the legitimate GitHub API for C2 communications (T1071.001 - Web Protocols). This makes it difficult for network defenders to distinguish malicious traffic from legitimate developer activity. The GitHub repository also hosted an in-memory wrapper for the open-source Chisel tunneling utility, which was used to bridge the compromised network with the attacker's external infrastructure (T1105 - Ingress Tool Transfer).

Impact Assessment

The Blinder Tunnel campaign poses a significant threat to critical infrastructure in the Middle East. By targeting software engineers and developers within these organizations, the attackers gain an initial foothold that can be leveraged for several malicious purposes:

  • Espionage: Gaining long-term access to sensitive networks to steal intellectual property, operational plans, and other confidential data.
  • Sabotage: The access could potentially be used to disrupt or disable critical services, although this has not been observed in this campaign.
  • Supply Chain Attacks: Compromising developers could allow the actor to inject malicious code into the organization's software products, creating a widespread supply chain attack.

While Dubai Airports was not breached, the impersonation of its brand damages its reputation and places its recruitment partners and potential candidates at risk. The targeting of individuals in Iraq, Israel, and the UAE indicates a broad regional focus for this threat actor. The primary business impact is the high risk of data exfiltration and the potential for operational disruption within compromised entities.

IOCs — Directly from Articles

The source article did not provide specific Indicators of Compromise (IOCs) such as file hashes, IP addresses, or domains, noting that the malicious GitHub infrastructure had been taken down.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns which could indicate related activity:

Type
File Name
Value
Dubai Airport Careers
Description
Name of the initial Inno Setup installer used in the lure.
Type
File Extension
Value
*.csproj
Description
Monitor for execution of C# project files outside of legitimate development tools like Visual Studio.
Type
Process Name
Value
Chisel
Description
Detection of the Chisel tunneling tool or its artifacts in memory or on disk.
Type
Network Traffic
Value
api.github.com
Description
Scrutinize traffic to the GitHub API from non-developer workstations or servers, especially if it involves unusual user agents or data patterns.
Type
Windows Event Log
Value
mscoree.dll
Description
Monitor for processes that are not part of the .NET framework unexpectedly loading mscoree.dll, which can be an indicator of AppDomainManager hijacking.

Detection & Response

Detecting the Blinder Tunnel campaign requires a multi-layered approach focusing on behavior rather than static signatures.

  • Endpoint Detection (EDR): Deploy EDR solutions capable of monitoring process execution chains. Create detection rules for the suspicious execution of .csproj files by non-standard parent processes. Monitor for known DLL sideloading patterns and the loading of mscoree.dll by unexpected applications. D3FEND's D3-PA - Process Analysis is a key technique here.
  • Network Monitoring: Implement network traffic analysis to baseline and monitor communications to cloud services like GitHub. While blocking GitHub is not feasible for many organizations, outbound traffic can be proxied and inspected. Look for anomalies such as large data transfers, non-standard user agents, or connections from servers that should not be communicating with GitHub. This aligns with D3-NTA - Network Traffic Analysis.
  • Log Analysis: Collect and analyze Windows Event Logs, specifically process creation events (Event ID 4688) and DLL loading events, to hunt for AppDomainManager hijacking and sideloading TTPs.

If a compromise is suspected, the immediate response should be to isolate the affected endpoints, preserve forensic evidence, and initiate an incident response investigation to determine the full scope of the breach.

Mitigation

Defending against this threat requires both technical controls and security awareness.

  • User Training: Educate employees, especially developers and engineers, about sophisticated social engineering attacks that abuse recruitment processes. This aligns with MITRE Mitigation M1017 - User Training.
  • Application Control: Implement application allowlisting policies to prevent the execution of unauthorized software and installers. Restricting the execution of .csproj files to only authorized developer tools can be an effective control. This relates to M1038 - Execution Prevention.
  • Harden Endpoints: Configure systems to mitigate DLL sideloading vulnerabilities. Ensure that application directories are properly permissioned.
  • Network Segmentation: Segment networks to limit lateral movement. Critical servers should not have direct, unrestricted access to the internet. Egress filtering to restrict outbound connections to only what is required for business purposes can help disrupt C2 channels. This is a form of M1030 - Network Segmentation.
  • Patch Management: While not a direct factor in this campaign's initial access, maintaining up-to-date systems is crucial for overall security posture and preventing other exploitation vectors. This aligns with M1051 - Update Software.

Timeline of Events

1
November 1, 2025
Threat actor begins staging and testing attack infrastructure for the Blinder Tunnel campaign.
2
March 1, 2026
The Blinder Tunnel campaign is activated, targeting an individual within Iraq's critical infrastructure sector.
3
May 1, 2026
A separate but related campaign is launched by the same actor against an Israeli entity using Google Drive lures.
4
October 6, 2026
Unit 42 publishes its research on the Blinder Tunnel campaign.
5
October 6, 2026
This article was published

MITRE ATT&CK Mitigations

Train employees, especially those in high-value roles like software development, to recognize and report sophisticated social engineering and recruitment fraud.

Use application control solutions to restrict the execution of unauthorized installers and scripts. Specifically, block the execution of .csproj files outside of approved developer environments.

Mapped D3FEND Techniques:

Filter and monitor outbound web traffic. While blocking GitHub may be impractical, proxying and inspecting traffic can help identify anomalous C2 communications.

Mapped D3FEND Techniques:

Implement egress filtering to block outbound connections from servers and workstations to non-essential destinations, disrupting potential C2 channels.

Mapped D3FEND Techniques:

Use modern EDR and antivirus solutions that employ behavioral analysis to detect suspicious process chains, DLL sideloading, and in-memory execution.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

To counter the Blinder Tunnel campaign's TTPs, organizations should implement advanced process analysis using an Endpoint Detection and Response (EDR) solution. This goes beyond simple signature-based detection. Configure EDR to monitor for anomalous process chains, specifically the execution of .csproj files by any process other than devenv.exe or other sanctioned developer tools. Create high-fidelity alerts for when a non-standard process (e.g., from an Inno Setup installer) spawns a process that loads the .NET runtime and begins compiling or executing a C# project. Furthermore, process analysis should be used to baseline normal DLL loading behavior for trusted applications. An alert should be triggered if a trusted system process is observed loading DLLs from non-standard directories, a key indicator of the DLL sideloading technique used by this actor. This technique is critical for detecting the initial execution and evasion stages of the Blinder Tunnel attack chain before the main payload is deployed.

Given the actor's use of the GitHub API for command and control, Network Traffic Analysis (NTA) is a crucial defensive measure. Organizations should deploy NTA tools or leverage SIEM capabilities to analyze NetFlow, proxy logs, and firewall logs. The goal is to establish a baseline of normal GitHub traffic within the environment. Detections should focus on identifying outliers from this baseline. For instance, a server in a production DMZ that has never communicated with api.github.com suddenly starting to do so would be a high-priority alert. Analyze the metadata of TLS connections to GitHub, looking for non-standard user agents or periodic, 'heartbeat'-like connections characteristic of C2 traffic. Correlate network data with endpoint process data; if a process that is not git.exe or a known developer tool is making sustained connections to GitHub, it warrants immediate investigation. This technique directly addresses the actor's 'living off the cloud' strategy by making it harder for their C2 traffic to hide in plain sight.

Implementing executable allowlisting provides a robust defense against the initial stages of the Blinder Tunnel attack. By defining a strict policy of what software is permitted to run, organizations can prevent the execution of the unauthorized Dubai Airport Careers Inno Setup installer. This should be deployed in 'enforce' mode on critical servers and for privileged user groups. For developer workstations, where more flexibility is needed, a more tailored policy can be created. For example, allow the execution of .csproj files only when initiated by a code-signed instance of Visual Studio (devenv.exe). This prevents the exact evasion technique used in this campaign, where a legitimate file type is abused by a malicious loader. While implementing a comprehensive allowlisting policy requires significant initial effort in baselining and policy tuning, it is one of the most effective ways to break this and many other attack chains at the execution stage.

Timeline of Events

1
November 1, 2025

Threat actor begins staging and testing attack infrastructure for the Blinder Tunnel campaign.

2
March 1, 2026

The Blinder Tunnel campaign is activated, targeting an individual within Iraq's critical infrastructure sector.

3
May 1, 2026

A separate but related campaign is launched by the same actor against an Israeli entity using Google Drive lures.

4
October 6, 2026

Unit 42 publishes its research on the Blinder Tunnel campaign.

Sources & References

Blinder Tunnel Campaign Targets Iraqi Infrastructure
Unit 42 (unit42.paloaltonetworks.com) •October 5, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Blinder TunnelIranAPTCritical InfrastructureSocial EngineeringGitHub C2ShelbyLoaderAppDomainManager HijackingDLL SideloadingChisel

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.