Threat reportAPTTL-2026-2986
Iranian State-Aligned Hackers Use Fake Dubai Airports Coding Test (Blinder Tunnel / CL-STA-1178) to Target Iraqi Critical Infrastructure
Iranian State-Aligned Hackers Use Fake Dubai Airports Coding (TL-2026-2986), also tracked as Blinder Tunnel, is a high-severity advanced persistent threat campaign, first published 2026-10-06. It is attributed to CL-STA-1178 (Iran) with medium confidence, affects Microsoft Visual Studio / .NET Framework (abused project evaluation, maps to 19 MITRE ATT&CK techniques (T1056.003, T1059.001, T1071.001), and is covered by 9 detection rules and 33 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 1CL-STA-1178
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-2986
- Threat ID
- TL-2026-2986
- Also known as
- Blinder Tunnel, ShelbyLoader V2, ShelbyC2 V2
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- CL-STA-1178
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- critical-infrastructure, aviation, telecoms, technology
- Target regions
- iraq, united arab emirates, israel
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in Iranian State-Aligned Hackers Use Fake Dubai Airports Coding
Malware and tooling: ShelbyC2 V2, ShelbyLoader V2, Chisel
How Iranian State-Aligned Hackers Use Fake Dubai Airports Coding works
Unit 42 tracks an Iranian state-aligned cluster, CL-STA-1178 (Blinder Tunnel), that posed as Dubai Airports IT recruiters and sent an Iraqi software engineer a trojanized Visual Studio coding test. The project deploys ShelbyLoader V2 and the ShelbyC2 V2 backdoor, with GitHub-API-based C2 and a Chisel-based tunneling module (Blackwood).
Blinder Tunnel (CL-STA-1178) is an Iranian state-aligned campaign disclosed by Palo Alto Networks Unit 42 on 2026-10-06. Infrastructure staging and testing was observed from November 2025; the campaign activated in March 2026 against an Iraqi software engineer, as a route into Iraqi critical infrastructure. The actor impersonated the Dubai Airports IT department. Stage one was a benign-looking Inno Setup 'Dubai Airport Careers' application that hosted a local imitation recruitment site and a 10-question HR form. It carried no malware, so it served only to build trust.
Stage two was an archive, DubaiAirport_Carrers_IT_Test.zip. Its Readme asked the candidate to open a C# Flight Management System project and fix a loop error. The weaponized FlightManager.csproj overrides the GetFrameworkPaths target, which Visual Studio invokes during background (design-time) evaluation. Opening the project is therefore enough to run code before any build. It copies files into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launches RuntimeBroker.exe, a renamed legitimate Microsoft vshost.exe binary. That binary side-loads the malicious RuntimeBroker.dll (ShelbyLoader V2). RuntimeBroker.exe.config replaces the .NET AppDomainManager so attacker code runs inside the trusted process, and it sets <etwEnable enabled="false"/> to disable Event Tracing for Windows.
ShelbyLoader V2 fingerprints the host, checks for virtualization and analysis artifacts (WMI, processes, registry, files) and requires explorer.exe as the parent. It persists through the HKCU Run value MicrosoftRuntime. It then uses a hard-coded GitHub personal access token to register the machine at /{machineId}/Lic.txt in the peakyblinders-tm/myLic repository and polls /{machineId}/Inf.txt for Base64 tasking. The beacon interval is 63 seconds, the persistence check is every 120 seconds, and the loader sleeps for one hour on an HTTP 403 rate limit. If the primary channel fails, a fallback searches GitHub Issues for AES-256-CBC ciphertext hidden in HTML comments. The key is derived from MD5(date + machineId) and yields the Owner, LicRepo and LicToken parameters. The loader decrypts ShelbyC2 V2 (RuntimeBrokerApi.dll), which is AES-CBC encrypted at rest with a key derived from the GitHub license content. ShelbyC2 V2 runs PowerShell through PsProxy.dll, a stateless in-memory engine that hooks System.Management.Automation.dll so powershell.exe is never spawned. It also stages Blackwood.dll, a .NET wrapper around a Go-compiled Chisel binary embedded as an 8.4 MB encrypted resource and loaded reflectively. Blackwood opens an encrypted reverse SOCKS tunnel (R:0.0.0.0:10999:socks) to 91.107.156.29 for internal pivoting.
Supporting activity: the Blackwood repository ('pubs') was created on 2026-05-01. From May to June 2026, 65.109.214.145 hosted Google Drive and Meet-themed credential-harvesting pages against an Israeli entity, using a conflict-themed WarUnPublishedDocuments.zip lure. The ShelbyLoader and ShelbyC2 lineage was previously documented by Elastic Security Labs ('The Shelby Strategy', REF8685), which targeted an Iraqi telecommunications organization and possibly Sharjah Airport. Unit 42 found no evidence that Dubai Airports itself was compromised.
Attribution to an Iranian nexus rests on Iranian ISP hosting for 87.248.129.239, Persian-language domain and registrar links on 91.107.156.29, an embedded MP3 whose metadata references MusicDel.ir, and regional victimology (Iraq, UAE, Israel). Unit 42 notes only low-confidence tradecraft overlaps with Screening Serpens (AppDomainManager hijacking, ETW disabling, aviation lures) and Agent Serpens (GitHub dead-drop C2, in-memory .NET PowerShell wrappers). The actor is therefore tracked as a separate cluster. Peaky Blinders references run through the infrastructure and malware naming. GitHub removed the actor's infrastructure after disclosure. No CVE is involved; the technique abuses Visual Studio's normal project-evaluation behavior.
MITRE ATT&CK techniques used in TL-2026-2986
Credential Access
T1056.003 Input Capture: Web Portal Capture
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1102.002 Web Service: Bidirectional Communication; T1572 Protocol Tunneling; T1573.001 Encrypted Channel: Symmetric Cryptography
Discovery
T1082 System Information Discovery
Defense Evasion
T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL; T1574.014 Hijack Execution Flow: AppDomainManager
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services
Reconnaissance
T1598.003 Phishing for Information: Spearphishing Link
defense-impairment
Affected products and versions in Iranian State-Aligned Hackers Use Fake Dubai Airports Coding
- Microsoft — Visual Studio / .NET Framework (abused project evaluation, AppDomainManager and ETW config)
Remediation for Iranian State-Aligned Hackers Use Fake Dubai Airports Coding
Immediate actions
- Block and hunt the listed IPs, phishing domains and GitHub accounts (peakyblinders-tm, GreenBeret0, ArthurShelby, JohnShelllby)
- Hunt for %LOCALAPPDATA%\Microsoft\RuntimeBrokers, RuntimeBroker.exe(.config) and the HKCU Run value MicrosoftRuntime
- Isolate hosts that opened the DubaiAirport_Carrers_IT_Test.zip project, and reset exposed credentials and GitHub tokens
Workarounds
- Alert on signed binaries loading unfamiliar DLLs from outside system directories
- Alert on unexpected developer projects, unusual MSBuild/Visual Studio child activity and modifications to .NET .config files
- Monitor GitHub API traffic that does not match development workflows
Longer-term hardening
- Verify recruiter and coding-test contacts through independent channels before opening any project
- Deploy phishing-resistant MFA and verify destination URLs before entering credentials
- Open untrusted Visual Studio projects only in isolated VMs
Timeline of Iranian State-Aligned Hackers Use Fake Dubai Airports Coding
- Unit 42 observes infrastructure staging and operational testing (reported at month precision: November 2025).
- Blinder Tunnel activates against an Iraqi software engineer, as a route into Iraqi critical infrastructure (month precision: March 2026).
- Fake Dubai Airports recruitment lure and the weaponized Visual Studio coding test (DubaiAirport_Carrers_IT_Test.zip) are delivered (month precision: April 2026).
- Encrypted fallback C2 data is planted in GitHub issue comments.
- The 'asasas' GitHub operational testing dashboard is created.
- The 'pubs' repository hosting the Blackwood Chisel tunneling tool is created.
- A VirusTotal submission from an Israeli IP address relates to the Google Drive-themed credential-harvesting lure.
- A credential-harvesting campaign against an Israeli entity (WarUnPublishedDocuments.zip lure) runs from May to June 2026 from 65.109.214.145.
- Unit 42 publicly discloses Blinder Tunnel (CL-STA-1178). GitHub subsequently removes the actor infrastructure.
Sources cited for Iranian State-Aligned Hackers Use Fake Dubai Airports Coding
- Blinder Tunnel Campaign Targets Iraqi Infrastructure (Unit 42)
- Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure (Cyber Security News)
- Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2 (GBHackers)
- The Shelby Strategy (Elastic Security Labs, REF8685)
- Iranian Hackers Use Fake Dubai Airports Coding Test (Cryptika)
- Iranian Hackers Pose as Recruiters: Fake Jobs, Malware and Cyber Espionage (Gulf News)
- Iranian hackers posed as recruiters and deployed malware to target aviation and oil engineers (Mezha)
Detection coverage for TL-2026-2986
As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2986 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.