GBHackers

DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data


DarkBlinders hackers are deploying a fake video meeting application and abusing GitHub repositories in a cyberespionage campaign targeting Israel and the Kurdistan Region of Iraq.

Dream researchers observed the operation between August and October 2026. The investigation confirmed compromises affecting a government cloud environment in Kurdistan and a prominent Israeli individual associated with the security sector.

DarkBlinders Hackers Use Fake Meeting App

Recovered operator tasking revealed credential theft and the exfiltration of at least 1 GB of government cloud data, providing direct visibility into the campaign’s impact.

The operation combines government webmail impersonation, fraudulent cloud sharing pages, and StarkMeet, a decoy meeting client. Phishing infrastructure mimicked Kuwait’s Ministry of Foreign Affairs and the Gulf Cooperation Council Secretariat General, indicating interest in diplomatic targets beyond the two confirmed victims.

Research workflow from RuntimeBroker.dll analysis (Source: dreamgroup)
Research workflow from RuntimeBroker.dll analysis (Source: dreamgroup)

StarkMeet’s unsigned Inno Setup installer presents version 3.2 of an apparently legitimate application. Camera, microphone, and screen previews work locally, but joining a meeting always generates a fixed connection error.

Researchers did not recover the original delivery message, leaving the initial distribution route unconfirmed. Meanwhile, the installer places malicious components under %LOCALAPPDATA%MicrosoftRuntimeBroker, separately from the visible application.

This arrangement allows the malware to survive removal of StarkMeet. A signed Microsoft vshost.exe, renamed RuntimeBroker.exe, loads RuntimeBroker.dll through an AppDomainManager mechanism.

The MicrosoftRuntime value in the current user’s Windows Run registry key establishes persistence. The loader uses an embedded GitHub token to register infected systems in the PeakyBlindersTeam/myLic repository.

Reports contain usernames, machine names, domains, keyboard layouts, persistence status, and anti-analysis findings, allowing operators to evaluate targets before activating the next stage.

Dreamgroup identified approximately ten initial host registrations but only two victims in the second-stage tasking repository. This discrepancy supports selective activation rather than automatic deployment.

 StarkMeet component and execution sequence. (Source: dreamgroup)
 StarkMeet component and execution sequence. (Source: dreamgroup)

For chosen systems, operators supply license material whose SHA-256 hash becomes the AES-256-CBC key used to decrypt RuntimeBrokerApi.dll. The decrypted assembly loads directly into memory.

The backdoor polls the separate myCode repository approximately every 63 seconds. Its embedded PsProxy.dll helper executes PowerShell through an internal runspace without launching powershell.exe, reducing visibility for detections dependent on that child process. Additional functions support file uploads, downloads, and ZIP extraction.

Both stages can recover replacement GitHub credentials from specially formatted comments in public Microsoft/vscode issues, potentially restoring communications after token revocation.

Dream linked the operation to four earlier campaign waves and assessed medium-to-high confidence overlap with UNC5795 and Dust Specter.

Relationships with UNC5187 and possible placement within APT34 carry medium confidence. Persian keyboard metadata and Iranian hosting associations provide context, but neither independently establishes attribution or identifies operators.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 



Source link