Iranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructure
Description
An Iranian state-aligned threat actor, CL-STA-1178, has been conducting the Blinder Tunnel campaign since November 2025, targeting Iraqi critical infrastructure by impersonating the Dubai Airports IT department. The campaign delivers trojanized coding challenges that deploy ShelbyLoader V2 malware through a multi-stage attack chain involving AppDomainManager hijacking and DLL sideloading. The attackers use GitHub API infrastructure for command-and-control communications, including repositories and issues as fallback channels. Operational security errors revealed links to a separate credential harvesting campaign targeting Israeli entities with conflict-themed Google Drive lures in mid-2026.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Blinder Tunnel campaign is an ongoing operation by the Iranian state-aligned threat actor CL-STA-1178 targeting Iraqi critical infrastructure. It uses social engineering by masquerading as Dubai Airports IT department to deliver trojanized coding challenges. The attack chain exploits legitimate Windows developer files, leveraging AppDomainManager hijacking and DLL sideloading to deploy ShelbyLoader V2 malware. Command-and-control is conducted via GitHub API infrastructure, with repositories used for decryption keys and payload downloads, and GitHub issues serving as fallback communication channels. The campaign incorporates cultural references from the Peaky Blinders television show in its infrastructure and malware. Operational security failures exposed connections to a separate credential harvesting operation targeting Israeli entities using Google Drive lures themed around regional conflict during May-June 2026.
Potential Impact
The campaign targets critical infrastructure in Iraq, potentially enabling espionage, disruption, or further compromise through the deployment of ShelbyLoader V2 malware. The use of sophisticated multi-stage techniques and abuse of legitimate infrastructure like GitHub complicates detection and mitigation. The exposure of related credential harvesting operations indicates broader regional targeting and operational scope.
Defensive Guidance
No official patch or remediation is indicated for this threat. Defenders should be aware of the social engineering tactics involving trojanized coding challenges impersonating trusted entities. Monitoring for AppDomainManager hijacking and DLL sideloading techniques, as well as unusual GitHub API activity, may aid detection. Since no vendor advisory or patch information is provided, patch status is not yet confirmed—check relevant vendor advisories for updates. Incident response should focus on containment and eradication of ShelbyLoader V2 malware if detected.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/"]
- Adversary
- CL-STA-1178
- Pulse Id
- 6ac6152430b84019d1fded71
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip87.248.129.239 | — | |
ip38.180.136.127 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 | — | |
hashf5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 | — | |
hash53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 | — | |
hash3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 | — | |
hash76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e | — | |
hashd3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 | — | |
hashf5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd | — | |
hash7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875 | — | |
hash2ab34636eeab843b4bcbb6e44f033eab | — | |
hash38aa0f535e2c6273ccf4de19a7a0f044 | — | |
hash3d809693b3d63f33126e9eb630fef8ff | — | |
hash5a796cdce448eddbf1aec1c7c186dacf | — | |
hash7244a27029d2fb104a598b40e9f284d9 | — | |
hash8a062a2d0741b57fab9635920b17275b | — | |
hashb53f5d8baf6840fa3a5ea8e56d208ddf | — | |
hashf2f8db8dc4c4f9573e5aa265235c9d49 | — | |
hash18586ca8e3e3c4633ed3fccd909a0be87ba0a573 | — | |
hash701f2a5c8d8bdc28e51e11a12955197fbd652698 | — | |
hash7fa5ce4031e57e608b4a2f92cacdaf9183dfe76a | — | |
hash8c839823f58e8965c770c900be2b2cf14e054871 | — | |
hash90f733c6aa7eaa37dbd654ef1f4cedfbb711dc03 | — | |
hash9842b996277682a136562aa27e08919eac542c15 | — | |
hashaa7f18c1552042d4d0854de69d5c69ee47a21ba2 | — | |
hashf320cd3c6de7efb61b59669ce70c81fc8a94758a | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaincloud.g-drive.cam | — | |
domaingoogeldrive.cam | — | |
domaindrivegoogel.cam | — | |
domaingoogelmeet.online | — | |
domainmeetonline.cam | — | |
domainasdfafadafg.online | — |
Threat ID: 6ac618ee2cdf04f65635fd2b
Added to database: 10/07/2026, 10:03:26 UTC
Last enriched: 10/07/2026, 10:18:24 UTC
Last updated: 10/07/2026, 18:48:08 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.