Overview of the Blinder Tunnel Campaign
Security researchers have uncovered a targeted cyber espionage operation tracked as Blinder Tunnel, directed against Iraqi critical infrastructure. According to Unit 42, an Iranian state-aligned threat actor designated as CL-STA-1178 orchestrated the campaign. The activity leverages sophisticated social engineering, masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value technical personnel. Infrastructure staging for this operation began as early as November 2025, culminating in active targeting by March 2026.
The threat group draws heavy inspiration from the television show “Peaky Blinders,” embedding thematic naming conventions throughout their infrastructure and even including the show’s theme song within their custom payloads. Alongside operations targeting Iraq, operational security errors linked this cluster to concurrent credential harvesting against Israeli entities using conflict-themed Google Drive lures.
Technical Analysis and Execution Chain
The initial intrusion vector relies on a carefully crafted social engineering scheme. Attackers approach software engineers with fake recruitment opportunities, directing them to download an Inno Setup installer disguised as a career portal. Targets must complete a technical assessment via a fake login screen, which subsequently drops custom malware known as ShelbyLoader V2.
The attack chain utilizes a multi-step execution process designed to evade traditional endpoint detection and response solutions:
- .csproj File Weaponization: The initial payload leverages a native Microsoft developer project file to initiate execution.
- AppDomainManager Hijacking: Attackers abuse native .NET mechanisms to force trusted Windows applications to load malicious assemblies.
- DLL Sideloading: Subsequent stages execute custom payloads via legitimate application side-loading.
Living Off the Cloud with GitHub C2
For command-and-control (C2) communication, the threat actor misuses legitimate developer platforms, a tactic commonly referred to as living off the cloud. Specifically, the operators leveraged GitHub repositories to manage communications and host an in-memory wrapper. This wrapper deployed the open-source Chisel tunneling utility, establishing a bridge between external attacker infrastructure and compromised internal networks.
Operational security missteps by the threat actors allowed researchers to connect these intrusions to broader Middle Eastern targeting across the telecommunications and aviation sectors.
Mitigations and Defense Recommendations
Defenders operating within high-risk sectors or managing developer endpoints should prioritize specific detection and hardening measures:
- Monitor Developer File Execution: Audit and restrict the execution of untrusted
.csprojfiles and monitor for anomalous usage of developer utilities outside of approved software development environments. - Detect AppDomainManager Hijacking: Implement rigorous endpoint monitoring to detect unauthorized modifications or unexpected registry configurations related to .NET AppDomain managers.
- Inspect Cloud API Traffic: Analyse enterprise network telemetry for suspicious or anomalous API traffic patterns communicating with code repository hosting platforms like GitHub.
- User Awareness Training: Train engineering teams to recognize recruitment-themed social engineering lures that request the installation of standalone offline application packages or unverified career portals.
Related: Browser Attacks and EDR Blind Spots: Mitigating SaaS Threats, 39 Methods Compromise Passkey Authentication: Threat Analysis