Skip to content

Image: unit42.paloaltonetworks.com · rights & removal

Executive Summary

An Iranian state-aligned threat actor was identified operating under the campaign name "Blinder Tunnel," targeting critical infrastructure across Iraq, Israel, and the UAE. This activity included a social engineering effort impersonating Dubai Airports to recruit targets, involving a phishing lure of a job offer that led to downloading an Inno Setup installer. The subsequent phase involved a weaponized Microsoft Visual Studio project archive, which contained a coding challenge with an intentional bug designed for exploitation. The infection chain involved exploiting legitimate .csproj files, performing AppDomainManager hijacking, and executing binaries via DLL sideloading to deploy custom malware, ShelbyLoader V2. Command and control (C2) communication utilized the GitHub API infrastructure by leveraging repositories for downloading payloads and using GitHub issues as a fallback mechanism. Further analysis revealed attackers used tools like PsProxy.dll for stealthy PowerShell execution and Blackwood, a Chisel tunneling tool, to establish encrypted network tunnels using a specific IP address. Attribution suggests an Iranian nexus based on infrastructure ownership, metadata artifacts, and alignment with established regional threat tactics.

Facts Only

* Activity tracked as CL-STA-1178 involves an Iranian state-aligned threat actor.
* The campaign was named "Blinder Tunnel" and targeted Iraqi critical infrastructure in March 2026, following staging observed in November 2025.
* Initial access involved exploiting legitimate Windows developer .csproj files.
* The infection chain included AppDomainManager hijacking followed by DLL sideloading to deploy ShelbyLoader V2 malware.
* C2 communication utilized GitHub API infrastructure for fetching decryption keys and downloading payloads.
* Attackers used a fallback mechanism via GitHub Issues for C2 communication.
* The execution chain involved using a PowerShell proxy module, PsProxy.dll.
* A custom tunneling tool named Blackwood.dll was deployed to establish encrypted TCP tunnels over HTTP with SOCKS5 proxy support.
* The final RAT payload was ShelbyC2 V2, loaded via RuntimeBrokerApi.dll.
* Attribution is based on Iranian-hosted infrastructure and embedded metadata referencing Iranian platforms.

Full Take

The narrative demonstrates a sophisticated evolution of an attack framework that intentionally weaves thematic elements ("Peaky Blinders") with technical execution to mask its origins and operational goals. The reliance on living-off-the-cloud techniques, specifically abusing GitHub APIs for C2, highlights a strategic choice designed to blend malicious activity into legitimate enterprise patterns. This suggests a playbook where infrastructure leverage is prioritized over stealth alone. The multi-stage malware development—from initial file execution via .csproj hijacking through complex in-memory manipulation and DLL sideloading—indicates an actor with deep knowledge of the Windows development ecosystem, utilizing built-in trust mechanisms against defensive tools like ETW. The fallback mechanism using GitHub issues for exfiltrating data demonstrates operational resilience, anticipating potential takedowns of primary infrastructure. The attribution points toward a state-aligned nexus, suggesting that this is not merely opportunistic cybercrime but a structured campaign reflecting established regional espionage playbooks adapted with specific cultural and thematic identifiers. The implication is that defense must shift from solely blocking known indicators to scrutinizing the provenance of developer artifacts and cloud interactions, recognizing that operational security failures are often integrated into the attack methodology itself.
Bridge Questions: If an actor intentionally embeds themes like "Peaky Blinders" and uses infrastructure linked to Iranian entities, how does this thematic branding serve as a specific signal or cultural marker within their wider geopolitical objectives? What is the long-term strategic value of utilizing GitHub issues as a C2 fallback versus maintaining a purely direct channel? How can security tooling evolve to prioritize anomaly detection across developer-centric operations rather than focusing solely on traditional perimeter defense?

From the original · Unit 42 Palo Alto Networks

Executive Summary We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178.
Read the full story at unit42.paloaltonetworks.com

Sentinel — Human

Confidence

This analysis reads like a highly detailed forensic report synthesized by human analysts, focusing on pattern discovery and attribution based on linked evidence.

Signals Detected
low severity: High variation in sentence structure and dense incorporation of specific technical jargon suggests human authoring rather than machine uniformity.
low severity: The text maintains a highly specialized, deeply interconnected narrative flow that is characteristic of in-depth forensic reporting, despite the dense data.
low severity: Extensive use of specific artifact names (CL-STA-1178, ShelbyLoader V2, Blinder Tunnel) and highly detailed cross-referencing strongly suggests a single investigative team's narrative structure.
low severity: The presence of concrete, verifiable links to specific IP addresses, known infrastructure (Hetzner), and documented external research (Elastic Security Labs, VirusTotal) suggests grounded sourcing rather than pure hallucination.
Human Indicators
Idiosyncratic emphasis on thematic elements ('Peaky Blinders') woven into the technical narrative.
The structure relies heavily on synthesizing disparate findings (operational testing, attribution artifacts) rather than simply listing facts.
Blinder Tunnel Campaign Targets Iraqi Infrastructure | Huntaegis