IndustrialCyber

Unit 42 links Blinder Tunnel campaign to Iranian state-aligned threat actor targeting aviation, telecommunications


Palo Alto Networks’ Unit 42 identified an Iranian state-aligned cyber threat campaign, dubbed Blinder Tunnel, targeting Iraqi critical infrastructure through recruitment-themed social engineering and custom malware. The campaign, tracked as CL-STA-1178, became active in March 2026 after attackers began staging and testing infrastructure in November 2025. 

Despite utilizing cloud infrastructure and code obfuscation to hide their operations, the actors behind the Blinder Tunnel campaign left behind several forensic artifacts. Based on infrastructure ownership, embedded metadata, targeted victimology and overlaps in tradecraft, Unit 42 assesses that an Iranian state-aligned threat actor conducted this campaign.

According to Unit 42, the threat actors impersonated the Dubai Airports IT department to target an individual in Iraq’s critical infrastructure sector, using a fake recruitment portal and a trojanized Microsoft Visual Studio coding challenge to deliver malware. The researchers assessed with high confidence that the activity was linked to an Iranian-nexus threat actor, with targeting extending across telecommunications, aviation and other critical entities in Iraq, Israel and the United Arab Emirates. 

Blinder Tunnel campaign uses a three-stage infection chain involving malicious Windows developer project files, AppDomainManager hijacking and dynamic-link library (DLL) sideloading to deploy custom malware, including the ShelbyLoader V2 loader, ShelbyC2 V2 remote access trojan and Blackwood tunneling tool. 

Unit 42 found that the attackers misused GitHub’s application programming interfaces to disguise command-and-control communications as legitimate cloud traffic, while GitHub issues provided a fallback mechanism for maintaining communications if primary infrastructure became unavailable. 

The Blackwood tool leveraged the open-source Chisel tunneling utility to establish encrypted connections and support movement across compromised networks. Researchers also linked the campaign’s infrastructure to a separate May-June 2026 credential-harvesting operation targeting an Israeli entity. GitHub has taken down the malicious infrastructure identified in the investigation, Unit 42 said, highlighting the need for organizations to secure developer environments, monitor anomalous cloud-platform traffic and remain alert to recruitment-themed social engineering.

CL-STA-1178 represents activity from an Iranian state-aligned threat actor linked to a series of targeted cyber operations across the Middle East. Previously associated with campaigns tracked by Elastic Security Labs as The Shelby Strategy, the threat actor behind this cluster of activity frequently employs thematic branding in their malware and infrastructure, drawing inspiration from the popular television show ‘Peaky Blinders.’

“The attackers behind this cluster target high-value infrastructure, including telecommunications, aviation and other critical entities across Iraq, Israel and the United Arab Emirates (UAE),” Unit 42 researchers identified in its blog post. “Since the launch of Blinder Tunnel in March 2026, Unit 42 researchers have identified an evolution in the operational capabilities associated with the activity. The attackers used tailored social engineering tactics, weaponizing recruitment lures aimed at Iraqi software developers and engineers.”

They added, “We observed the threat actor staging and testing attack infrastructure as early as November 2025. This infrastructure remained dormant but operational until March 2026, when the attackers activated the campaign to target an individual in Iraq’s critical infrastructure sector.”

Starting in late March 2026, a threat actor ran a social engineering campaign disguised as a professional recruitment process, apparently aimed at compromising a specific individual, likely a software engineer. The campaign was identified through multiple file submissions to VirusTotal from a submitter based in Iraq. Impersonating the Dubai Airports IT department, the attackers approached the target with a job offer for a development role. As a mandatory first step in the recruitment process, the target was told to download and install a file named Dubai Airport Careers, which deployed an offline site posing as a careers portal. 

To access the supposed assessment, the target had to log in with credentials supplied by the fake recruiters, making the experience feel like a genuine portal. Unit 42 noted that threat actors often abuse legitimate products and brands for malicious purposes, which does not imply any flaw in them, and said it is not aware of any breach, compromise or vulnerability within Dubai Airports’ infrastructure or systems.

In April 2026, the same source that had reported the fake career portal to VirusTotal made another submission, revealing the next stage of the recruitment lure. Unlike the usual malicious links or documents seen in Iranian Dream Job campaigns, the threat actor sent the target a weaponized Microsoft Visual Studio project archive disguised as a coding assessment. 

The archive included a personalized Readme file in which a supposed senior manager of a Dubai Airports IT department asked the target to open a Flight Management System project and complete a short at-home task. The task involved finding and fixing a deliberately planted bug, something an experienced software engineer could do without difficulty. Before this, the fake career portal had acted as a harmless decoy, with its questionnaire triggering no malicious activity, which was designed to build credibility and lower the victim’s guard.

The infection began the moment the target opened the project in their development environment, even before any attempt to compile the code. Attackers abused the way the development tool routinely performs background checks when a project is loaded, causing hidden malware to be copied to a folder disguised as a legitimate Microsoft component and launched while the developer was still reading the instructions. 

Malware then ran inside a trusted, legitimate Microsoft process, which gave it a cover of normal activity and allowed the attackers to switch off a Windows monitoring mechanism that helps detect threats, impairing detection capabilities. The attack chain concluded with a final stage in which the attackers exploited a weakness in the renamed Microsoft program to load their malicious payload into memory.

Attackers relied on a modular, multi-stage set of custom tools built for persistence, remote command execution and lateral movement across compromised environments, including a loader, a primary backdoor, a PowerShell execution component and a tunneling utility. All of the .NET binaries recovered in the campaign were obscured with an open-source obfuscation tool, which makes reverse engineering and automated analysis harder. 

Organizations can defend against such attacks by monitoring for programs that load unknown or non-standard components from outside system directories and by watching for abnormal process behavior. In this case, Cortex XDR flagged the activity as high severity and blocked it before any user interaction could occur.

Throughout the campaign, the attackers performed operational testing to validate and improve their infrastructure and malware functions. The attackers confirmed dead-drop C2 resolution through GitHub comments in November 2025 and simulated Iraqi connections on a mock GitHub issue dashboard in April 2026. We also observed that the attackers tested additional infrastructure on a staging server for a phishing campaign targeting an Israeli entity in May 2026.

Unit 42 noted that analysis of Blackwood tunneling configurations submitted to VirusTotal revealed additional attacker infrastructure active between May and June 2026. One of the servers showed that the attackers reused the same infrastructure for both internal network access and credential harvesting. Research linked this server to a phishing campaign from May to June 2026 targeting an Israeli entity, using conflict-themed lures.

Several findings led to the attribution of this activity to an Iranian-linked actor. The initial Blackwood command-and-control IP address belongs to an Iranian internet service provider, TOSE’EH ERTEBATAT NOVIN ARIA, while a secondary tunneling server hosted with Hetzner resolves to Persian-language domains that the attackers likely acquired through an Iranian reseller. In addition, an .mp3 file hosted in the attackers’ public GitHub repository retained metadata pointing to MusicDel[.]ir, a popular Iranian music platform.

The campaign’s targeting profile also aligns with previously documented regional espionage activity and with historical targeting patterns associated with this activity cluster. Furthermore, the campaign employed established Iranian tactics, techniques and procedures, which show low-confidence overlaps between CL-STA-1178 and established Iranian groups.

Among these tactics were the use of aviation-targeted lures and AppDomainManager hijacking to disable ETW, which resembles the behavior of Screening Serpens. The attackers also used GitHub dead-drop resolvers and in-memory .NET PowerShell wrappers, the latter resembling the activity of Agent Serpens.

The activity tracked as CL-STA-1178 represents targeted operations against Middle Eastern enterprise networks in the newly uncovered Blinder Tunnel campaign. The attackers used tailored social engineering to masquerade as Dubai Airports recruiters, relying on a trojanized Visual Studio coding challenge to target a high-value job seeker based in Iraq.

The campaign is characterized by the misuse of built-in developer tools and DLL sideloading, while AppDomainManager hijacking was used to bypass security monitors such as ETW. These evasion techniques enabled the attackers to deploy their primary loader, ShelbyLoader V2, their custom RAT payload, ShelbyC2 V2, and their custom Blackwood tunneling tool.

The Blinder Tunnel campaign also relied on living-off-the-cloud techniques. By misusing GitHub APIs and reading encrypted comments within GitHub issues to rotate command-and-control servers, the attackers disguised the malware’s command traffic as legitimate enterprise platform activity.

“We assess with high confidence that this activity cluster aligns with the work of an Iranian-nexus threat actor. The attacker using infrastructure themed around the TV show ‘Peaky Blinders’ links this activity to the campaign previously documented in Elastic Security’s ‘The Shelby Strategy’ report,” Unit 42 identified. “Furthermore, OpSec failures and flawed cryptography uncovered a parallel campaign targeting an Israeli entity, revealing a broader operational footprint. The campaign’s tool set and geographical targeting align with established regional threat activity and historical tradecraft.”

The researchers added that this operation underscores the need for organizations to secure developer environments, monitor anomalous cloud platform traffic and maintain vigilance against industry-specific social engineering lures.



Source link