Image: unit42.paloaltonetworks.com · rights & removal
Blinder Tunnel Campaign Targets Iraqi Infrastructure
Reporting by Unit 42 Palo Alto NetworksRead the original at unit42.paloaltonetworks.com
Executive Summary
Facts Only
* Activity tracked as CL-STA-1178 involves an Iranian state-aligned threat actor.
* The campaign was named "Blinder Tunnel" and targeted Iraqi critical infrastructure in March 2026, following staging observed in November 2025.
* Initial access involved exploiting legitimate Windows developer .csproj files.
* The infection chain included AppDomainManager hijacking followed by DLL sideloading to deploy ShelbyLoader V2 malware.
* C2 communication utilized GitHub API infrastructure for fetching decryption keys and downloading payloads.
* Attackers used a fallback mechanism via GitHub Issues for C2 communication.
* The execution chain involved using a PowerShell proxy module, PsProxy.dll.
* A custom tunneling tool named Blackwood.dll was deployed to establish encrypted TCP tunnels over HTTP with SOCKS5 proxy support.
* The final RAT payload was ShelbyC2 V2, loaded via RuntimeBrokerApi.dll.
* Attribution is based on Iranian-hosted infrastructure and embedded metadata referencing Iranian platforms.
Full Take
The narrative demonstrates a sophisticated evolution of an attack framework that intentionally weaves thematic elements ("Peaky Blinders") with technical execution to mask its origins and operational goals. The reliance on living-off-the-cloud techniques, specifically abusing GitHub APIs for C2, highlights a strategic choice designed to blend malicious activity into legitimate enterprise patterns. This suggests a playbook where infrastructure leverage is prioritized over stealth alone. The multi-stage malware development—from initial file execution via .csproj hijacking through complex in-memory manipulation and DLL sideloading—indicates an actor with deep knowledge of the Windows development ecosystem, utilizing built-in trust mechanisms against defensive tools like ETW. The fallback mechanism using GitHub issues for exfiltrating data demonstrates operational resilience, anticipating potential takedowns of primary infrastructure. The attribution points toward a state-aligned nexus, suggesting that this is not merely opportunistic cybercrime but a structured campaign reflecting established regional espionage playbooks adapted with specific cultural and thematic identifiers. The implication is that defense must shift from solely blocking known indicators to scrutinizing the provenance of developer artifacts and cloud interactions, recognizing that operational security failures are often integrated into the attack methodology itself.
Bridge Questions: If an actor intentionally embeds themes like "Peaky Blinders" and uses infrastructure linked to Iranian entities, how does this thematic branding serve as a specific signal or cultural marker within their wider geopolitical objectives? What is the long-term strategic value of utilizing GitHub issues as a C2 fallback versus maintaining a purely direct channel? How can security tooling evolve to prioritize anomaly detection across developer-centric operations rather than focusing solely on traditional perimeter defense?
From the original · Unit 42 Palo Alto Networks
Executive Summary We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178.Read the full story at unit42.paloaltonetworks.com
Sentinel — Human
This analysis reads like a highly detailed forensic report synthesized by human analysts, focusing on pattern discovery and attribution based on linked evidence.
