Iranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructure
An Iranian state-aligned threat actor designated as CL-STA-1178 has been impersonating the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. The Blinder Tunnel campaign, active since November 2025 with attacks intensifying in March 2026, primarily targeted Iraqi critical infrastructure. The operation employs a three-step attack chain exploiting legitimate Windows developer files, AppDomainManager hijacking, and DLL sideloading to deploy ShelbyLoader V2 malware. Attackers abuse GitHub API infrastructure for command-and-control communications, utilizing repositories for decryption keys, payload downloads, and GitHub issues as fallback mechanisms. The campaign incorporates Peaky Blinders television show themes in its infrastructure naming and embeds the show's theme song in malware. Operational security failures exposed connections to a separate credential harvesting operation targeting Israeli entities using conflict-themed Google Drive lures during May-June 2026.
Pulse ID: 6ac6152430b84019d1fded71
Pulse Link: https://otx.alienvault.com/pulse/6ac6152430b84019d1fded71
Pulse Author: AlienVault
Created: 2026-10-07 09:47:16
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #Deliver #Deploy #GitHub #OTX #AlienVault