Skip to main content
MEDIUM Threat Intel #Ransomware#Zero-Day#Phishing

Blinder Tunnel Campaign Targets Iraqi Critical Infrastructure

3 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • An Iranian state-aligned threat actor targeted Iraqi critical infrastructure and regional aviation entities using customized social engineering lures.
  • Software engineers and high-value technical personnel in telecommunications and aviation sectors are affected by the Blinder Tunnel campaign.
  • Defenders must monitor for AppDomainManager hijacking, inspect .csproj execution chains, and review unauthorized GitHub API traffic.

Advertisement

Overview of the Blinder Tunnel Campaign

Security researchers have uncovered a targeted cyber espionage operation tracked as Blinder Tunnel, directed against Iraqi critical infrastructure. According to Unit 42, an Iranian state-aligned threat actor designated as CL-STA-1178 orchestrated the campaign. The activity leverages sophisticated social engineering, masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value technical personnel. Infrastructure staging for this operation began as early as November 2025, culminating in active targeting by March 2026.

The threat group draws heavy inspiration from the television show “Peaky Blinders,” embedding thematic naming conventions throughout their infrastructure and even including the show’s theme song within their custom payloads. Alongside operations targeting Iraq, operational security errors linked this cluster to concurrent credential harvesting against Israeli entities using conflict-themed Google Drive lures.

Technical Analysis and Execution Chain

The initial intrusion vector relies on a carefully crafted social engineering scheme. Attackers approach software engineers with fake recruitment opportunities, directing them to download an Inno Setup installer disguised as a career portal. Targets must complete a technical assessment via a fake login screen, which subsequently drops custom malware known as ShelbyLoader V2.

The attack chain utilizes a multi-step execution process designed to evade traditional endpoint detection and response solutions:

  • .csproj File Weaponization: The initial payload leverages a native Microsoft developer project file to initiate execution.
  • AppDomainManager Hijacking: Attackers abuse native .NET mechanisms to force trusted Windows applications to load malicious assemblies.
  • DLL Sideloading: Subsequent stages execute custom payloads via legitimate application side-loading.

Living Off the Cloud with GitHub C2

For command-and-control (C2) communication, the threat actor misuses legitimate developer platforms, a tactic commonly referred to as living off the cloud. Specifically, the operators leveraged GitHub repositories to manage communications and host an in-memory wrapper. This wrapper deployed the open-source Chisel tunneling utility, establishing a bridge between external attacker infrastructure and compromised internal networks.

Operational security missteps by the threat actors allowed researchers to connect these intrusions to broader Middle Eastern targeting across the telecommunications and aviation sectors.

Mitigations and Defense Recommendations

Defenders operating within high-risk sectors or managing developer endpoints should prioritize specific detection and hardening measures:

  • Monitor Developer File Execution: Audit and restrict the execution of untrusted .csproj files and monitor for anomalous usage of developer utilities outside of approved software development environments.
  • Detect AppDomainManager Hijacking: Implement rigorous endpoint monitoring to detect unauthorized modifications or unexpected registry configurations related to .NET AppDomain managers.
  • Inspect Cloud API Traffic: Analyse enterprise network telemetry for suspicious or anomalous API traffic patterns communicating with code repository hosting platforms like GitHub.
  • User Awareness Training: Train engineering teams to recognize recruitment-themed social engineering lures that request the installation of standalone offline application packages or unverified career portals.

Related: Browser Attacks and EDR Blind Spots: Mitigating SaaS Threats, 39 Methods Compromise Passkey Authentication: Threat Analysis

Advertisement

Advertisement