Blinder Tunnel Campaign Targets Iraqi Infrastructure
Description
The Blinder Tunnel campaign is an Iranian state-aligned cyber operation targeting Iraqi critical infrastructure using sophisticated social engineering and malware delivery techniques. The attackers impersonated the Dubai Airports IT department to lure targets with fake recruitment portals and coding challenges. The infection chain involves exploiting Windows developer project files, AppDomainManager hijacking, and DLL sideloading to deploy custom malware called ShelbyLoader V2. The campaign uses GitHub API infrastructure for command-and-control communications, blending malicious traffic with legitimate cloud activity. GitHub has taken down the malicious repositories associated with this campaign. The campaign also links to other operations targeting Israeli entities with credential harvesting lures. This activity was observed from November 2025 and activated in March 2026.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Blinder Tunnel is a cyber espionage campaign attributed with high confidence to an Iranian state-aligned threat actor tracked as CL-STA-1178. It targets high-value infrastructure sectors in Iraq and the broader Middle East. The attackers use a multi-stage infection chain starting with weaponized .csproj files, followed by AppDomainManager hijacking and DLL sideloading to deploy ShelbyLoader V2 malware. Command-and-control communications misuse GitHub's API and repositories, including fallback via GitHub issues, to evade detection. The campaign employs social engineering via fake Dubai Airports recruitment portals and coding challenges to gain initial access. Operational security errors by the attackers helped researchers link this campaign to other Iranian-nexus operations involving credential harvesting against Israeli targets. GitHub has removed the malicious infrastructure used in this campaign.
Potential Impact
The campaign targets critical infrastructure entities, potentially enabling espionage, covert access, and persistent presence within victim networks. The use of advanced evasion techniques like AppDomainManager hijacking and living-off-the-cloud C2 communications increases the difficulty of detection and mitigation. The campaign's focus on high-value targets in Iraq's critical infrastructure sector and related operations against Israeli entities indicates significant geopolitical targeting. The compromise of credentials and deployment of custom malware could lead to data exfiltration, network control, or disruption of critical services.
Defensive Guidance
GitHub has taken down the malicious repositories used for command-and-control in this campaign, disrupting attacker infrastructure. Palo Alto Networks customers are protected through Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Cortex XDR, and XSIAM products. Organizations should be aware of social engineering tactics involving fake recruitment lures and coding challenges, especially impersonating trusted entities like Dubai Airports. Monitoring for AppDomainManager hijacking and DLL sideloading techniques is recommended. Contacting incident response teams such as Unit 42 is advised if compromise is suspected. No official patch is applicable as this is a targeted campaign using social engineering and malware delivery rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/","fetched":true,"fetchedAt":"2026-10-06T10:05:57.018Z","wordCount":6739}
Threat ID: 6ac4c8052cdf04f65697004d
Added to database: 10/06/2026, 10:05:57 UTC
Last enriched: 10/06/2026, 10:06:02 UTC
Last updated: 10/06/2026, 13:21:16 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.