Iranian-Aligned Blinder Tunnel Campaign Targets Iraqi Critical Infrastructure

· Original article ↗

Summary

Unit 42 details a campaign that used fake Dubai Airports recruitment lures and a trojanized Visual Studio project to target an Iraqi infrastructure-sector individual, deploying malware that used GitHub for command and control.

Key points

  • Unit 42 attributes the activity, tracked as CL-STA-1178, with high confidence to an Iranian state-aligned actor; infrastructure staging dates to November 2025, with the campaign targeting Iraq in March 2026.
  • The attackers impersonated Dubai Airports recruiters and delivered a malicious C# coding challenge to a likely software engineer. Unit 42 says it found no breach or compromise of Dubai Airports systems.
  • Opening the weaponized .csproj file in Visual Studio triggered execution, followed by AppDomainManager hijacking and DLL sideloading; the hijack could disable Event Tracing for Windows (ETW).
  • The toolset included ShelbyLoader V2, the ShelbyC2 V2 backdoor, an in-memory PowerShell execution module, and Blackwood, which deployed Chisel for encrypted tunneling and network pivoting.
  • The malware used GitHub APIs and repository issues for command and control, retrieving payloads and encrypted fallback instructions. GitHub took down infrastructure identified by Unit 42.
  • Unit 42 linked the activity to a separate May–June 2026 campaign using conflict-themed lures and lookalike Google domains to harvest credentials from an Israeli entity.

Article Details

Attack Vectors
  • CL-STA-1178 impersonated Dubai Airports recruiters and sent a targeted individual in Iraq a trojanized Visual Studio coding challenge.
  • Opening the project caused Visual Studio's design-time build to execute attacker-defined instructions in a weaponized .csproj file, copying and launching hidden malware.
  • The infection chain used AppDomainManager hijacking and DLL sideloading to run ShelbyLoader V2 through a renamed, signed Microsoft hosting binary.
  • ShelbyLoader V2 used GitHub repository files for command-and-control and searched encrypted GitHub issue comments for fallback connection details.
  • A linked operation used Google-themed phishing domains and conflict-themed lures against an Israeli entity; Blackwood configurations linked credential-harvesting infrastructure with tunneling infrastructure.
Defensive Notes
  • Monitor developer project files for unexpected build targets and execution during project loading.
  • Monitor signed binaries loading unknown or non-standard DLLs outside system directories, and investigate configuration changes that disable ETW.
  • Monitor anomalous GitHub API traffic and Chisel tunneling attempts. Unit 42 reported that GitHub removed the malicious infrastructure it identified.
  • Google said its Drive systems were not compromised and advised phishing-resistant multi-factor authentication and verification of destination URLs before entering credentials.
  • Unit 42 reported that Cortex XDR detected and blocked the observed execution chain.

Indicators of compromise

TypeIndicatorContext
DOMAINasdfafadafg[.]onlineDomain linked to the attackers' earlier phishing-infrastructure staging server.
DOMAINcloud[.]g-drive[.]camAttacker-used phishing domain hosting a Google Drive-themed lure and impersonated login page.
DOMAINdrivegoogel[.]camGoogle-themed phishing domain hosted on the attackers' infrastructure.
DOMAINgoogeldrive[.]camGoogle-themed phishing domain hosted on the attackers' infrastructure.
DOMAINgoogelmeet[.]onlineDomain listed by Unit 42 as phishing infrastructure.
DOMAINmeetonline[.]camDomain listed by Unit 42 as phishing infrastructure.
HOSTNAMEportal[.]sharjahairport[.]cloudMalicious subdomain that Elastic Security Labs linked to related UAE aviation-sector targeting.
IPV438[.]180[.]136[.]127Secondary server linked to the attackers' earlier phishing-infrastructure testing.
IPV465[.]109[.]214[.]145Server linked to Blackwood and the credential-harvesting infrastructure.
IPV487[.]248[.]129[.]239Address listed by Unit 42 among the campaign's indicators and contacted by a Blackwood archive.
IPV491[.]107[.]156[.]29Blackwood tunneling endpoint configured to establish a reverse SOCKS proxy.
SHA2563fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13PsProxy.dll in-memory PowerShell execution module.
SHA25653f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402RuntimeBroker.dll malware loader identified as ShelbyLoader V2.
SHA2566e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239Initial malicious coding-challenge archive, DubaiAirport_Carrers_IT_Test.zip.
SHA25676273382e4252c1f60a2251141e108942494409c759358320735891762c0682eBlackwood.dll malicious Chisel tunneling wrapper.
SHA2567cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875Blackwood archive configured to contact 87.248.129[.]239.
SHA256d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260Blackwood configuration contacting the tunneling endpoint 91.107.156[.]29.
SHA256f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9Weaponized Visual Studio project file, FlightManager.csproj.
SHA256f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bdBlackwood archive configured to contact 65.109.214[.]145.
URLhxxps[:]//github[.]com/GreenBeret0GitHub URL listed by Unit 42 as campaign C2 infrastructure.
URLhxxps[:]//github[.]com/peakyblinders-tmGitHub account URL listed by Unit 42 as campaign C2 infrastructure.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe recovered .NET binaries were obscured with Obfuscar, including runtime string decryption and non-printable Unicode identifiers.T1059.001 · PowerShellPsProxy.dll executed attacker-supplied PowerShell scripts through an in-process runspace without spawning PowerShell.exe.T1102.002 · Bidirectional CommunicationShelbyLoader V2 uploaded host information to, and retrieved tasking from, files in an attacker-used GitHub repository.T1102.003 · One-Way CommunicationAs a C2 fallback, ShelbyLoader V2 searched GitHub issues and extracted encrypted routing details from issue comments.T1127.001 · MSBuildA custom GetFrameworkPaths target in the malicious .csproj file caused the project's design-time build to copy and launch malware.T1497.001 · System ChecksShelbyLoader V2 checked virtualization markers in WMI, processes, registry keys and files, as well as host hardware, before running.T1547.001 · Registry Run Keys / Startup FolderShelbyLoader V2 created a MicrosoftRuntime value under the current user's startup registry key to launch RuntimeBroker.exe.T1562.002 · Disable Windows Event LoggingThe malicious application configuration used an etwEnable directive set to false, which Unit 42 said could impair ETW-based detection.T1566.001 · Spearphishing AttachmentAttackers sent the targeted developer a weaponized Visual Studio project archive disguised as a recruitment coding assessment.T1572 · Protocol TunnelingBlackwood loaded Chisel to establish encrypted TCP tunnels over HTTP with reverse SOCKS proxy support.T1574.001 · DLLThe renamed Microsoft binary loaded the attackers' RuntimeBroker.dll; a later execution chain sideloaded Blackwood.dll.T1574.014 · AppDomainManagerAttackers altered RuntimeBroker.exe.config to make a renamed Visual Studio hosting process execute their AppDomainManager.

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles