Skip to main content

Iranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructure

0
Medium
Published: 10/07/2026 (10/07/2026, 09:47:16 UTC)
Source: AlienVault OTX General

Description

An Iranian state-aligned threat actor, CL-STA-1178, has been conducting the Blinder Tunnel campaign since November 2025, targeting Iraqi critical infrastructure by impersonating the Dubai Airports IT department. The campaign delivers trojanized coding challenges that deploy ShelbyLoader V2 malware through a multi-stage attack chain involving AppDomainManager hijacking and DLL sideloading. The attackers use GitHub API infrastructure for command-and-control communications, including repositories and issues as fallback channels. Operational security errors revealed links to a separate credential harvesting campaign targeting Israeli entities with conflict-themed Google Drive lures in mid-2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 10:18:24 UTC

Technical Analysis

The Blinder Tunnel campaign is an ongoing operation by the Iranian state-aligned threat actor CL-STA-1178 targeting Iraqi critical infrastructure. It uses social engineering by masquerading as Dubai Airports IT department to deliver trojanized coding challenges. The attack chain exploits legitimate Windows developer files, leveraging AppDomainManager hijacking and DLL sideloading to deploy ShelbyLoader V2 malware. Command-and-control is conducted via GitHub API infrastructure, with repositories used for decryption keys and payload downloads, and GitHub issues serving as fallback communication channels. The campaign incorporates cultural references from the Peaky Blinders television show in its infrastructure and malware. Operational security failures exposed connections to a separate credential harvesting operation targeting Israeli entities using Google Drive lures themed around regional conflict during May-June 2026.

Potential Impact

The campaign targets critical infrastructure in Iraq, potentially enabling espionage, disruption, or further compromise through the deployment of ShelbyLoader V2 malware. The use of sophisticated multi-stage techniques and abuse of legitimate infrastructure like GitHub complicates detection and mitigation. The exposure of related credential harvesting operations indicates broader regional targeting and operational scope.

Defensive Guidance

No official patch or remediation is indicated for this threat. Defenders should be aware of the social engineering tactics involving trojanized coding challenges impersonating trusted entities. Monitoring for AppDomainManager hijacking and DLL sideloading techniques, as well as unusual GitHub API activity, may aid detection. Since no vendor advisory or patch information is provided, patch status is not yet confirmed—check relevant vendor advisories for updates. Incident response should focus on containment and eradication of ShelbyLoader V2 malware if detected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/"]
Adversary
CL-STA-1178
Pulse Id
6ac6152430b84019d1fded71

Indicators of Compromise

Ip

ValueDescriptionCopy
ip87.248.129.239
—
ip38.180.136.127
—

Hash

ValueDescriptionCopy
hash6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239
—
hashf5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9
—
hash53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402
—
hash3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13
—
hash76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e
—
hashd3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260
—
hashf5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd
—
hash7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875
—
hash2ab34636eeab843b4bcbb6e44f033eab
—
hash38aa0f535e2c6273ccf4de19a7a0f044
—
hash3d809693b3d63f33126e9eb630fef8ff
—
hash5a796cdce448eddbf1aec1c7c186dacf
—
hash7244a27029d2fb104a598b40e9f284d9
—
hash8a062a2d0741b57fab9635920b17275b
—
hashb53f5d8baf6840fa3a5ea8e56d208ddf
—
hashf2f8db8dc4c4f9573e5aa265235c9d49
—
hash18586ca8e3e3c4633ed3fccd909a0be87ba0a573
—
hash701f2a5c8d8bdc28e51e11a12955197fbd652698
—
hash7fa5ce4031e57e608b4a2f92cacdaf9183dfe76a
—
hash8c839823f58e8965c770c900be2b2cf14e054871
—
hash90f733c6aa7eaa37dbd654ef1f4cedfbb711dc03
—
hash9842b996277682a136562aa27e08919eac542c15
—
hashaa7f18c1552042d4d0854de69d5c69ee47a21ba2
—
hashf320cd3c6de7efb61b59669ce70c81fc8a94758a
—

Domain

ValueDescriptionCopy
domaincloud.g-drive.cam
—
domaingoogeldrive.cam
—
domaindrivegoogel.cam
—
domaingoogelmeet.online
—
domainmeetonline.cam
—
domainasdfafadafg.online
—

Threat ID: 6ac618ee2cdf04f65635fd2b

Added to database: 10/07/2026, 10:03:26 UTC

Last enriched: 10/07/2026, 10:18:24 UTC

Last updated: 10/07/2026, 18:48:08 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses