Threat reportAPTTL-2026-2986

Iranian State-Aligned Hackers Use Fake Dubai Airports Coding Test (Blinder Tunnel / CL-STA-1178) to Target Iraqi Critical Infrastructure

highACTIVE

Iranian State-Aligned Hackers Use Fake Dubai Airports Coding (TL-2026-2986), also tracked as Blinder Tunnel, is a high-severity advanced persistent threat campaign, first published 2026-10-06. It is attributed to CL-STA-1178 (Iran) with medium confidence, affects Microsoft Visual Studio / .NET Framework (abused project evaluation, maps to 19 MITRE ATT&CK techniques (T1056.003, T1059.001, T1071.001), and is covered by 9 detection rules and 33 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
1CL-STA-1178
Detection rules
9SPL · KQL · Sigma
IOCs
33Indicators of compromise

Key facts for TL-2026-2986

Threat ID
TL-2026-2986
Also known as
Blinder Tunnel, ShelbyLoader V2, ShelbyC2 V2
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
CL-STA-1178
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
critical-infrastructure, aviation, telecoms, technology
Target regions
iraq, united arab emirates, israel
Detection rules
9
Indicators of compromise
33

Malware and tooling in Iranian State-Aligned Hackers Use Fake Dubai Airports Coding

Malware and tooling: ShelbyC2 V2, ShelbyLoader V2, Chisel

How Iranian State-Aligned Hackers Use Fake Dubai Airports Coding works

Unit 42 tracks an Iranian state-aligned cluster, CL-STA-1178 (Blinder Tunnel), that posed as Dubai Airports IT recruiters and sent an Iraqi software engineer a trojanized Visual Studio coding test. The project deploys ShelbyLoader V2 and the ShelbyC2 V2 backdoor, with GitHub-API-based C2 and a Chisel-based tunneling module (Blackwood).

Blinder Tunnel (CL-STA-1178) is an Iranian state-aligned campaign disclosed by Palo Alto Networks Unit 42 on 2026-10-06. Infrastructure staging and testing was observed from November 2025; the campaign activated in March 2026 against an Iraqi software engineer, as a route into Iraqi critical infrastructure. The actor impersonated the Dubai Airports IT department. Stage one was a benign-looking Inno Setup 'Dubai Airport Careers' application that hosted a local imitation recruitment site and a 10-question HR form. It carried no malware, so it served only to build trust.

Stage two was an archive, DubaiAirport_Carrers_IT_Test.zip. Its Readme asked the candidate to open a C# Flight Management System project and fix a loop error. The weaponized FlightManager.csproj overrides the GetFrameworkPaths target, which Visual Studio invokes during background (design-time) evaluation. Opening the project is therefore enough to run code before any build. It copies files into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launches RuntimeBroker.exe, a renamed legitimate Microsoft vshost.exe binary. That binary side-loads the malicious RuntimeBroker.dll (ShelbyLoader V2). RuntimeBroker.exe.config replaces the .NET AppDomainManager so attacker code runs inside the trusted process, and it sets <etwEnable enabled="false"/> to disable Event Tracing for Windows.

ShelbyLoader V2 fingerprints the host, checks for virtualization and analysis artifacts (WMI, processes, registry, files) and requires explorer.exe as the parent. It persists through the HKCU Run value MicrosoftRuntime. It then uses a hard-coded GitHub personal access token to register the machine at /{machineId}/Lic.txt in the peakyblinders-tm/myLic repository and polls /{machineId}/Inf.txt for Base64 tasking. The beacon interval is 63 seconds, the persistence check is every 120 seconds, and the loader sleeps for one hour on an HTTP 403 rate limit. If the primary channel fails, a fallback searches GitHub Issues for AES-256-CBC ciphertext hidden in HTML comments. The key is derived from MD5(date + machineId) and yields the Owner, LicRepo and LicToken parameters. The loader decrypts ShelbyC2 V2 (RuntimeBrokerApi.dll), which is AES-CBC encrypted at rest with a key derived from the GitHub license content. ShelbyC2 V2 runs PowerShell through PsProxy.dll, a stateless in-memory engine that hooks System.Management.Automation.dll so powershell.exe is never spawned. It also stages Blackwood.dll, a .NET wrapper around a Go-compiled Chisel binary embedded as an 8.4 MB encrypted resource and loaded reflectively. Blackwood opens an encrypted reverse SOCKS tunnel (R:0.0.0.0:10999:socks) to 91.107.156.29 for internal pivoting.

Supporting activity: the Blackwood repository ('pubs') was created on 2026-05-01. From May to June 2026, 65.109.214.145 hosted Google Drive and Meet-themed credential-harvesting pages against an Israeli entity, using a conflict-themed WarUnPublishedDocuments.zip lure. The ShelbyLoader and ShelbyC2 lineage was previously documented by Elastic Security Labs ('The Shelby Strategy', REF8685), which targeted an Iraqi telecommunications organization and possibly Sharjah Airport. Unit 42 found no evidence that Dubai Airports itself was compromised.

Attribution to an Iranian nexus rests on Iranian ISP hosting for 87.248.129.239, Persian-language domain and registrar links on 91.107.156.29, an embedded MP3 whose metadata references MusicDel.ir, and regional victimology (Iraq, UAE, Israel). Unit 42 notes only low-confidence tradecraft overlaps with Screening Serpens (AppDomainManager hijacking, ETW disabling, aviation lures) and Agent Serpens (GitHub dead-drop C2, in-memory .NET PowerShell wrappers). The actor is therefore tracked as a separate cluster. Peaky Blinders references run through the infrastructure and malware naming. GitHub removed the actor's infrastructure after disclosure. No CVE is involved; the technique abuses Visual Studio's normal project-evaluation behavior.

MITRE ATT&CK techniques used in TL-2026-2986

Credential Access

T1056.003 Input Capture: Web Portal Capture

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1102.002 Web Service: Bidirectional Communication; T1572 Protocol Tunneling; T1573.001 Encrypted Channel: Symmetric Cryptography

Discovery

T1082 System Information Discovery

Defense Evasion

T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL; T1574.014 Hijack Execution Flow: AppDomainManager

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services

Reconnaissance

T1598.003 Phishing for Information: Spearphishing Link

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Iranian State-Aligned Hackers Use Fake Dubai Airports Coding

  • Microsoft — Visual Studio / .NET Framework (abused project evaluation, AppDomainManager and ETW config)

Remediation for Iranian State-Aligned Hackers Use Fake Dubai Airports Coding

Immediate actions

  • Block and hunt the listed IPs, phishing domains and GitHub accounts (peakyblinders-tm, GreenBeret0, ArthurShelby, JohnShelllby)
  • Hunt for %LOCALAPPDATA%\Microsoft\RuntimeBrokers, RuntimeBroker.exe(.config) and the HKCU Run value MicrosoftRuntime
  • Isolate hosts that opened the DubaiAirport_Carrers_IT_Test.zip project, and reset exposed credentials and GitHub tokens

Workarounds

  • Alert on signed binaries loading unfamiliar DLLs from outside system directories
  • Alert on unexpected developer projects, unusual MSBuild/Visual Studio child activity and modifications to .NET .config files
  • Monitor GitHub API traffic that does not match development workflows

Longer-term hardening

  • Verify recruiter and coding-test contacts through independent channels before opening any project
  • Deploy phishing-resistant MFA and verify destination URLs before entering credentials
  • Open untrusted Visual Studio projects only in isolated VMs

Timeline of Iranian State-Aligned Hackers Use Fake Dubai Airports Coding

  • Unit 42 observes infrastructure staging and operational testing (reported at month precision: November 2025).
  • Blinder Tunnel activates against an Iraqi software engineer, as a route into Iraqi critical infrastructure (month precision: March 2026).
  • Fake Dubai Airports recruitment lure and the weaponized Visual Studio coding test (DubaiAirport_Carrers_IT_Test.zip) are delivered (month precision: April 2026).
  • Encrypted fallback C2 data is planted in GitHub issue comments.
  • The 'asasas' GitHub operational testing dashboard is created.
  • The 'pubs' repository hosting the Blackwood Chisel tunneling tool is created.
  • A VirusTotal submission from an Israeli IP address relates to the Google Drive-themed credential-harvesting lure.
  • A credential-harvesting campaign against an Israeli entity (WarUnPublishedDocuments.zip lure) runs from May to June 2026 from 65.109.214.145.
  • Unit 42 publicly discloses Blinder Tunnel (CL-STA-1178). GitHub subsequently removes the actor infrastructure.

Sources cited for Iranian State-Aligned Hackers Use Fake Dubai Airports Coding

Detection coverage for TL-2026-2986

As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2986 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
33 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats