Iranian-Aligned Blinder Tunnel Campaign Targets Iraqi Critical Infrastructure

Summary
Unit 42 details a campaign that used fake Dubai Airports recruitment lures and a trojanized Visual Studio project to target an Iraqi infrastructure-sector individual, deploying malware that used GitHub for command and control.
Key points
- Unit 42 attributes the activity, tracked as CL-STA-1178, with high confidence to an Iranian state-aligned actor; infrastructure staging dates to November 2025, with the campaign targeting Iraq in March 2026.
- The attackers impersonated Dubai Airports recruiters and delivered a malicious C# coding challenge to a likely software engineer. Unit 42 says it found no breach or compromise of Dubai Airports systems.
- Opening the weaponized .csproj file in Visual Studio triggered execution, followed by AppDomainManager hijacking and DLL sideloading; the hijack could disable Event Tracing for Windows (ETW).
- The toolset included ShelbyLoader V2, the ShelbyC2 V2 backdoor, an in-memory PowerShell execution module, and Blackwood, which deployed Chisel for encrypted tunneling and network pivoting.
- The malware used GitHub APIs and repository issues for command and control, retrieving payloads and encrypted fallback instructions. GitHub took down infrastructure identified by Unit 42.
- Unit 42 linked the activity to a separate May–June 2026 campaign using conflict-themed lures and lookalike Google domains to harvest credentials from an Israeli entity.
Article Details
- Attack Vectors
- CL-STA-1178 impersonated Dubai Airports recruiters and sent a targeted individual in Iraq a trojanized Visual Studio coding challenge.
- Opening the project caused Visual Studio's design-time build to execute attacker-defined instructions in a weaponized .csproj file, copying and launching hidden malware.
- The infection chain used AppDomainManager hijacking and DLL sideloading to run ShelbyLoader V2 through a renamed, signed Microsoft hosting binary.
- ShelbyLoader V2 used GitHub repository files for command-and-control and searched encrypted GitHub issue comments for fallback connection details.
- A linked operation used Google-themed phishing domains and conflict-themed lures against an Israeli entity; Blackwood configurations linked credential-harvesting infrastructure with tunneling infrastructure.
- Defensive Notes
- Monitor developer project files for unexpected build targets and execution during project loading.
- Monitor signed binaries loading unknown or non-standard DLLs outside system directories, and investigate configuration changes that disable ETW.
- Monitor anomalous GitHub API traffic and Chisel tunneling attempts. Unit 42 reported that GitHub removed the malicious infrastructure it identified.
- Google said its Drive systems were not compromised and advised phishing-resistant multi-factor authentication and verification of destination URLs before entering credentials.
- Unit 42 reported that Cortex XDR detected and blocked the observed execution chain.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | asdfafadafg[.]online | Domain linked to the attackers' earlier phishing-infrastructure staging server. |
| DOMAIN | cloud[.]g-drive[.]cam | Attacker-used phishing domain hosting a Google Drive-themed lure and impersonated login page. |
| DOMAIN | drivegoogel[.]cam | Google-themed phishing domain hosted on the attackers' infrastructure. |
| DOMAIN | googeldrive[.]cam | Google-themed phishing domain hosted on the attackers' infrastructure. |
| DOMAIN | googelmeet[.]online | Domain listed by Unit 42 as phishing infrastructure. |
| DOMAIN | meetonline[.]cam | Domain listed by Unit 42 as phishing infrastructure. |
| HOSTNAME | portal[.]sharjahairport[.]cloud | Malicious subdomain that Elastic Security Labs linked to related UAE aviation-sector targeting. |
| IPV4 | 38[.]180[.]136[.]127 | Secondary server linked to the attackers' earlier phishing-infrastructure testing. |
| IPV4 | 65[.]109[.]214[.]145 | Server linked to Blackwood and the credential-harvesting infrastructure. |
| IPV4 | 87[.]248[.]129[.]239 | Address listed by Unit 42 among the campaign's indicators and contacted by a Blackwood archive. |
| IPV4 | 91[.]107[.]156[.]29 | Blackwood tunneling endpoint configured to establish a reverse SOCKS proxy. |
| SHA256 | 3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 | PsProxy.dll in-memory PowerShell execution module. |
| SHA256 | 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 | RuntimeBroker.dll malware loader identified as ShelbyLoader V2. |
| SHA256 | 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 | Initial malicious coding-challenge archive, DubaiAirport_Carrers_IT_Test.zip. |
| SHA256 | 76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e | Blackwood.dll malicious Chisel tunneling wrapper. |
| SHA256 | 7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875 | Blackwood archive configured to contact 87.248.129[.]239. |
| SHA256 | d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 | Blackwood configuration contacting the tunneling endpoint 91.107.156[.]29. |
| SHA256 | f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 | Weaponized Visual Studio project file, FlightManager.csproj. |
| SHA256 | f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd | Blackwood archive configured to contact 65.109.214[.]145. |
| URL | hxxps[:]//github[.]com/GreenBeret0 | GitHub URL listed by Unit 42 as campaign C2 infrastructure. |
| URL | hxxps[:]//github[.]com/peakyblinders-tm | GitHub account URL listed by Unit 42 as campaign C2 infrastructure. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe recovered .NET binaries were obscured with Obfuscar, including runtime string decryption and non-printable Unicode identifiers.T1059.001 · PowerShellPsProxy.dll executed attacker-supplied PowerShell scripts through an in-process runspace without spawning PowerShell.exe.T1102.002 · Bidirectional CommunicationShelbyLoader V2 uploaded host information to, and retrieved tasking from, files in an attacker-used GitHub repository.T1102.003 · One-Way CommunicationAs a C2 fallback, ShelbyLoader V2 searched GitHub issues and extracted encrypted routing details from issue comments.T1127.001 · MSBuildA custom GetFrameworkPaths target in the malicious .csproj file caused the project's design-time build to copy and launch malware.T1497.001 · System ChecksShelbyLoader V2 checked virtualization markers in WMI, processes, registry keys and files, as well as host hardware, before running.T1547.001 · Registry Run Keys / Startup FolderShelbyLoader V2 created a MicrosoftRuntime value under the current user's startup registry key to launch RuntimeBroker.exe.T1562.002 · Disable Windows Event LoggingThe malicious application configuration used an etwEnable directive set to false, which Unit 42 said could impair ETW-based detection.T1566.001 · Spearphishing AttachmentAttackers sent the targeted developer a weaponized Visual Studio project archive disguised as a recruitment coding assessment.T1572 · Protocol TunnelingBlackwood loaded Chisel to establish encrypted TCP tunnels over HTTP with reverse SOCKS proxy support.T1574.001 · DLLThe renamed Microsoft binary loaded the attackers' RuntimeBroker.dll; a later execution chain sideloaded Blackwood.dll.T1574.014 · AppDomainManagerAttackers altered RuntimeBroker.exe.config to make a renamed Visual Studio hosting process execute their AppDomainManager.
Threat Actors
Malware
BlackwoodBlackwood: Loader running in-memory tunneling utility (Chisel)DrokbkDrokbk Malware Uses GitHub as Dead Drop Resolver – SophosPowerLess TrojanPowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage – Cybereason NocturnusPsProxy.dllPsProxy.dll: PowerShell execution engineShelbyC2ShelbyC2 V2: Primary backdoorShelbyC2 V2ShelbyC2 V2: Primary backdoorShelbyLoaderThese steps enabled the attackers to deploy custom malware that we refer to as ShelbyLoader V2.ShelbyLoader V2These steps enabled the attackers to deploy custom malware that we refer to as ShelbyLoader V2.
Vendors
GitHubTo blend in with legitimate cloud traffic, the campaign misused GitHub’s API infrastructure for command-and-control (C2) communication.GoogleThese tactical errors linked Blinder Tunnel infrastructure to a separate campaign in which the same actor leveraged conflict-themed Google Drive lures for credential harvesting against an Israeli entity in May-June 2026.HetznerA secondary Hetzner tunneling server resolves to Persian-language domains that the attackers likely acquired via an Iranian reseller.MicrosoftThe attacks introduced a new layer of evasion by weaponizing a native .csproj file, a Microsoft developer file used to build software projects.Palo Alto NetworksPalo Alto Networks customers are better protected from the Blinder Tunnel campaign through the following products and services:
Products
Advanced DNS SecurityAdvanced URL Filtering and Advanced DNS SecurityAdvanced URL FilteringAdvanced URL Filtering and Advanced DNS SecurityAdvanced WildFireAdvanced WildFireCortex AgentiX Agentic AssistantCortex AgentiX Agentic Assistant streamlined this investigation.Cortex XDRCortex XDR and XSIAMGitHubTo blend in with legitimate cloud traffic, the campaign misused GitHub’s API infrastructure for command-and-control (C2) communication.Google ChromeGoogle Safe Browsing and Chrome protections actively block access to these identified malicious domains.Google DriveThese tactical errors linked Blinder Tunnel infrastructure to a separate campaign in which the same actor leveraged conflict-themed Google Drive lures for credential harvesting against an Israeli entity in May-June 2026.Google Safe BrowsingGoogle Safe Browsing and Chrome protections actively block access to these identified malicious domains.Google WorkspaceThe threat actors utilized external lookalike domains designed to impersonate Google Drive and Google Workspace interfaces for credential harvesting.Microsoft WindowsExploited legitimate Windows developer .csproj filesVisual StudioSecurity about Iranian Dream Job campaigns, the threat actor sent the target a weaponized Microsoft Visual Studio project archive disguised as a coding assessment.XSIAMCortex XDR and XSIAM
Tools
ChiselBefore its removal, the GitHub repository also hosted an in-memory wrapper that executed the open-source Chisel tunneling utility.ObfuscarAll the .NET binaries recovered in this campaign were obscured with the open-source obfuscator Obfuscar.VirusTotalWe identified this campaign through VirusTotal, following multiple file submissions from a submitter based in Iraq.
Countries
GermanyAlthough this server is hosted on Hetzner's infrastructure in Germany, passive DNS telemetry links it to an external domain layout.Iranis an active, public Iranian music distribution website used primarily for downloading tracks in Iran. The presence of this specific metadata string indicates that the operators downloaded the audio file fromIraqThe attackers behind this cluster target high-value infrastructure, including telecommunications, aviation and other critical entities across Iraq, Israel and the United Arab Emirates (UAE).IsraelThe attackers behind this cluster target high-value infrastructure, including telecommunications, aviation and other critical entities across Iraq, Israel and the United Arab Emirates (UAE).United Arab EmiratesThe attackers behind this cluster target high-value infrastructure, including telecommunications, aviation and other critical entities across Iraq, Israel and the United Arab Emirates (UAE).
Industries
AviationThe attackers behind this cluster target high-value infrastructure, including telecommunications, aviation and other critical entities across Iraq, Israel and the United Arab Emirates (UAE).Critical infrastructureThis activity includes a campaign we call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging that was observed as early as November 2025.TelecommunicationsThe attackers behind this cluster target high-value infrastructure, including telecommunications, aviation and other critical entities across Iraq, Israel and the United Arab Emirates (UAE).