An Iranian state-aligned hacking group impersonated the IT department of Dubai Airports to plant malware on a target in Iraq’s critical infrastructure sector, according to research published Tuesday by Unit 42, Palo Alto Networks’ threat intelligence arm. The same group also ran a credential-harvesting campaign against an Israeli entity in May and June, using war-themed lures.
Unit 42 tracks the activity as CL-STA-1178 and calls the Iraq operation “Blinder Tunnel,” after the “Peaky Blinders” branding the attackers used across their infrastructure. Their GitHub accounts are named after the British crime drama and its characters, and one repository embedded the show’s theme song. Unit 42 assesses with high confidence that the activity is Iranian-nexus, but found only low-confidence overlaps with known Iranian groups such as Screening Serpens (UNC1549) and Agent Serpens (APT35, also known as Charming Kitten), not enough to attribute it to either.
1 View gallery

An Iranian state-aligned hacking group impersonated the IT department of Dubai Airports.
(Photo: Shutterstock)
The campaign went live in late March 2026, using infrastructure that had been staged as early as November 2025 and left dormant. The target, likely an Iraq-based software engineer, was first asked to install a fake Dubai Airports careers portal and complete a harmless 10-question HR questionnaire, a step Unit 42 says was designed to build trust. In April came the real payload: a Visual Studio project pitched as a 15-to-20-minute coding test, with a planted bug for the candidate to find and fix.
The trap fired before any code was compiled. The attackers rigged the project file so that Visual Studio’s routine background build, which runs as soon as a project is opened, silently copied and launched their malware. From there, the chain hijacked a legitimate, signed Microsoft process, switched off a Windows event-tracing mechanism security tools rely on, and loaded a custom loader Unit 42 calls ShelbyLoader V2.
Instead of a conventional command server, the malware took its orders through GitHub, pulling commands and decryption keys from repositories and falling back on encrypted instructions hidden in GitHub issue comments if its access token was revoked. A tunneling tool called Blackwood, a wrapper for the open-source Chisel utility, gave the attackers a covert path into the victim’s internal network. GitHub has since taken the infrastructure down.
The attackers’ own mistakes tied the pieces together. The theme-song MP3 in their public repository still carried metadata pointing to an Iranian music download site, and one server sat on an Iranian ISP. Reused infrastructure also linked Blinder Tunnel to the Israeli campaign: a Google Drive lookalike page offering a file named “WarUnPublishedDocuments.zip,” which led to a fake Google login page. Unit 42 did not name the Israeli target. Google told Unit 42 its systems were not compromised, and Unit 42 said it is not aware of any breach at Dubai Airports.
According to Unit 42, this is the first report to tie several previously documented attacks, including activity Elastic Security Labs described as “The Shelby Strategy,” into a single tracked cluster. The group has previously targeted telecom and aviation organizations in Iraq, Israel and the UAE.
Click Here For The Original Source.
