# Iranian State-Aligned Hackers Use Fake Dubai Airports Coding Test (Blinder Tunnel / CL-STA-1178) to Target Iraqi Critical Infrastructure

> Unit 42 tracks an Iranian state-aligned cluster, CL-STA-1178 (Blinder Tunnel), that posed as Dubai Airports IT recruiters and sent an Iraqi software engineer a trojanized Visual Studio coding test. The project deploys ShelbyLoader V2 and the ShelbyC2 V2 backdoor, with GitHub-API-based C2 and a Chisel-based tunneling module (Blackwood).

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2986
- **ID:** TL-2026-2986
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** CL-STA-1178 (Iran)
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Blinder Tunnel (CL-STA-1178) is an Iranian state-aligned campaign disclosed by Palo Alto Networks Unit 42 on 2026-10-06. Infrastructure staging and testing was observed from November 2025; the campaign activated in March 2026 against an Iraqi software engineer, as a route into Iraqi critical infrastructure. The actor impersonated the Dubai Airports IT department. Stage one was a benign-looking Inno Setup 'Dubai Airport Careers' application that hosted a local imitation recruitment site and a 10-question HR form. It carried no malware, so it served only to build trust.

Stage two was an archive, DubaiAirport_Carrers_IT_Test.zip. Its Readme asked the candidate to open a C# Flight Management System project and fix a loop error. The weaponized FlightManager.csproj overrides the GetFrameworkPaths target, which Visual Studio invokes during background (design-time) evaluation. Opening the project is therefore enough to run code before any build. It copies files into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launches RuntimeBroker.exe, a renamed legitimate Microsoft vshost.exe binary. That binary side-loads the malicious RuntimeBroker.dll (ShelbyLoader V2). RuntimeBroker.exe.config replaces the .NET AppDomainManager so attacker code runs inside the trusted process, and it sets <etwEnable enabled="false"/> to disable Event Tracing for Windows.

ShelbyLoader V2 fingerprints the host, checks for virtualization and analysis artifacts (WMI, processes, registry, files) and requires explorer.exe as the parent. It persists through the HKCU Run value MicrosoftRuntime. It then uses a hard-coded GitHub personal access token to register the machine at /{machineId}/Lic.txt in the peakyblinders-tm/myLic repository and polls /{machineId}/Inf.txt for Base64 tasking. The beacon interval is 63 seconds, the persistence check is every 120 seconds, and the loader sleeps for one hour on an HTTP 403 rate limit. If the primary channel fails, a fallback searches GitHub Issues for AES-256-CBC ciphertext hidden in HTML comments. The key is derived from MD5(date + machineId) and yields the Owner, LicRepo and LicToken parameters. The loader decrypts ShelbyC2 V2 (RuntimeBrokerApi.dll), which is AES-CBC encrypted at rest with a key derived from the GitHub license content. ShelbyC2 V2 runs PowerShell through PsProxy.dll, a stateless in-memory engine that hooks System.Management.Automation.dll so powershell.exe is never spawned. It also stages Blackwood.dll, a .NET wrapper around a Go-compiled Chisel binary embedded as an 8.4 MB encrypted resource and loaded reflectively. Blackwood opens an encrypted reverse SOCKS tunnel (R:0.0.0.0:10999:socks) to 91.107.156.29 for internal pivoting.

Supporting activity: the Blackwood repository ('pubs') was created on 2026-05-01. From May to June 2026, 65.109.214.145 hosted Google Drive and Meet-themed credential-harvesting pages against an Israeli entity, using a conflict-themed WarUnPublishedDocuments.zip lure. The ShelbyLoader and ShelbyC2 lineage was previously documented by Elastic Security Labs ('The Shelby Strategy', REF8685), which targeted an Iraqi telecommunications organization and possibly Sharjah Airport. Unit 42 found no evidence that Dubai Airports itself was compromised.

Attribution to an Iranian nexus rests on Iranian ISP hosting for 87.248.129.239, Persian-language domain and registrar links on 91.107.156.29, an embedded MP3 whose metadata references MusicDel.ir, and regional victimology (Iraq, UAE, Israel). Unit 42 notes only low-confidence tradecraft overlaps with Screening Serpens (AppDomainManager hijacking, ETW disabling, aviation lures) and Agent Serpens (GitHub dead-drop C2, in-memory .NET PowerShell wrappers). The actor is therefore tracked as a separate cluster. Peaky Blinders references run through the infrastructure and malware naming. GitHub removed the actor's infrastructure after disclosure. No CVE is involved; the technique abuses Visual Studio's normal project-evaluation behavior.

## MITRE ATT&CK

- T1598.003 Phishing for Information: Spearphishing Link
- T1583.001 Acquire Infrastructure: Domains
- T1583.006 Acquire Infrastructure: Web Services
- T1566.002 Phishing: Spearphishing Link
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1574.001 DLL
- T1574.014 Hijack Execution Flow: AppDomainManager
- T1685 Disable or Modify Tools
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1082 System Information Discovery
- T1056.003 Input Capture: Web Portal Capture
- T1102.002 Web Service: Bidirectional Communication
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1572 Protocol Tunneling
- T1090 Proxy

## Sources

- [Blinder Tunnel Campaign Targets Iraqi Infrastructure (Unit 42)](https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/)
- [Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure (Cyber Security News)](https://cybersecuritynews.com/iranian-hackers/)
- [Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2 (GBHackers)](https://gbhackers.com/shelbyloader-v2-malware/)
- [The Shelby Strategy (Elastic Security Labs, REF8685)](https://www.elastic.co/security-labs/the-shelby-strategy)
- [Iranian Hackers Use Fake Dubai Airports Coding Test (Cryptika)](https://www.cryptika.com/iranian-hackers-use-fake-dubai-airports-coding-test-to-target-iraqi-critical-infrastructure/)
- [Iranian Hackers Pose as Recruiters: Fake Jobs, Malware and Cyber Espionage (Gulf News)](https://gulfnews.com/amp/story/world/mena/fake-jobs-hidden-malware-irans-cyber-spy-playbook-1.500550527)
- [Iranian hackers posed as recruiters and deployed malware to target aviation and oil engineers (Mezha)](https://mezha.net/eng/news/72bf6434_iranian_hackers_posed/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2986
