Skip to main content

Blinder Tunnel Campaign Targets Iraqi Infrastructure

0
High
Campaignmalware
Published: 10/06/2026 (10/06/2026, 10:00:33 UTC)
Source: Palo Alto Unit 42

Description

The Blinder Tunnel campaign is an Iranian state-aligned cyber operation targeting Iraqi critical infrastructure using sophisticated social engineering and malware delivery techniques. The attackers impersonated the Dubai Airports IT department to lure targets with fake recruitment portals and coding challenges. The infection chain involves exploiting Windows developer project files, AppDomainManager hijacking, and DLL sideloading to deploy custom malware called ShelbyLoader V2. The campaign uses GitHub API infrastructure for command-and-control communications, blending malicious traffic with legitimate cloud activity. GitHub has taken down the malicious repositories associated with this campaign. The campaign also links to other operations targeting Israeli entities with credential harvesting lures. This activity was observed from November 2025 and activated in March 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/06/2026, 10:06:02 UTC

Technical Analysis

Blinder Tunnel is a cyber espionage campaign attributed with high confidence to an Iranian state-aligned threat actor tracked as CL-STA-1178. It targets high-value infrastructure sectors in Iraq and the broader Middle East. The attackers use a multi-stage infection chain starting with weaponized .csproj files, followed by AppDomainManager hijacking and DLL sideloading to deploy ShelbyLoader V2 malware. Command-and-control communications misuse GitHub's API and repositories, including fallback via GitHub issues, to evade detection. The campaign employs social engineering via fake Dubai Airports recruitment portals and coding challenges to gain initial access. Operational security errors by the attackers helped researchers link this campaign to other Iranian-nexus operations involving credential harvesting against Israeli targets. GitHub has removed the malicious infrastructure used in this campaign.

Potential Impact

The campaign targets critical infrastructure entities, potentially enabling espionage, covert access, and persistent presence within victim networks. The use of advanced evasion techniques like AppDomainManager hijacking and living-off-the-cloud C2 communications increases the difficulty of detection and mitigation. The campaign's focus on high-value targets in Iraq's critical infrastructure sector and related operations against Israeli entities indicates significant geopolitical targeting. The compromise of credentials and deployment of custom malware could lead to data exfiltration, network control, or disruption of critical services.

Defensive Guidance

GitHub has taken down the malicious repositories used for command-and-control in this campaign, disrupting attacker infrastructure. Palo Alto Networks customers are protected through Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Cortex XDR, and XSIAM products. Organizations should be aware of social engineering tactics involving fake recruitment lures and coding challenges, especially impersonating trusted entities like Dubai Airports. Monitoring for AppDomainManager hijacking and DLL sideloading techniques is recommended. Contacting incident response teams such as Unit 42 is advised if compromise is suspected. No official patch is applicable as this is a targeted campaign using social engineering and malware delivery rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/","fetched":true,"fetchedAt":"2026-10-06T10:05:57.018Z","wordCount":6739}

Threat ID: 6ac4c8052cdf04f65697004d

Added to database: 10/06/2026, 10:05:57 UTC

Last enriched: 10/06/2026, 10:06:02 UTC

Last updated: 10/06/2026, 13:21:16 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses