Threat reportAPTTL-2026-3223
DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 to Deploy RuntimeBroker Backdoor Against Government Targets
DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 (TL-2026-3223), also tracked as StarkMeet campaign, is a high-severity advanced persistent threat campaign, first published 2026-10-10. It is attributed to DarkBlinders (Iran) with medium confidence, affects Microsoft Windows (endpoints executing the StarkMeet installer), maps to 17 MITRE ATT&CK techniques (T1008, T1036.005, T1059.001), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 1DarkBlinders
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-3223
- Threat ID
- TL-2026-3223
- Also known as
- StarkMeet campaign, PeakyBlinders
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- DarkBlinders
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- government administration, it - security, telecoms, aviation
- Target regions
- Middle East, iraq, israel, kuwait, GCC, united arab emirates
- Detection rules
- 9
- Indicators of compromise
- 34
How DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 works
DarkBlinders (assessed Iran-nexus; overlaps UNC5795 / Dust Specter) lures victims with webmail and cloud-drive phishing pages and a fake video-meeting client, StarkMeet, that installs a .NET AppDomainManager backdoor (RuntimeBroker.dll / RuntimeBrokerApi.dll / PsProxy.dll) controlled through GitHub repositories. Two confirmed victims: an Israeli security-sector individual and a Kurdistan Regional Government cloud environment (1+ GB exfiltrated).
Dream Research Labs (report published 2026-10-08, "DarkBlinders: Inside An Active Espionage Campaign") documents a campaign observed August-October 2026 and still active at publication. The operator combines credential-phishing pages that impersonate Outlook Web Access/webmail for Kuwait's Ministry of Foreign Affairs (mfakuwait lookalikes), the GCC Secretariat General (gcc-sg lookalikes) and Kurdistan Regional Government services (krgcloud, moelcloud), fraudulent cloud-drive and meeting pages (msonedrive, googedrive, drive-g, googemeet), and a fake meeting client named StarkMeet. The initial delivery route to the confirmed victims has not been confirmed in the sources.
The StarkMeet package (StarkMeet.zip) contains an unsigned Inno Setup installer presenting version 3.2 of a .NET decoy with Stark Industries branding. The decoy shows local camera, microphone and screen previews, but joining a meeting always returns a fixed connection error. The installer drops components into %LOCALAPPDATA%\Microsoft\RuntimeBroker so that the implant survives removal of the visible application. A signed Microsoft vshost.exe is renamed RuntimeBroker.exe and loads RuntimeBroker.dll through an AppDomainManager mechanism (a .config-driven .NET loading technique). Persistence is the HKCU Run value MicrosoftRuntime.
RuntimeBroker.dll is a loader. It uses an embedded GitHub token to register each infected host in the PeakyBlindersTeam/myLic repository, reporting username, machine name, domain, keyboard layout, persistence status and anti-analysis findings. Operators review this metadata and selectively activate victims: roughly 10 initial registrations were recovered and only 2 progressed to second-stage deployment. The second stage, RuntimeBrokerApi.dll, is decrypted with AES-256-CBC (PKCS7) using a key derived as SHA-256 of a license string, with the IV taken from the first 16 bytes of the key. It polls the myCode repository about every 63 seconds for commands (/up, /dl, /de, /rate, plus PowerShell execution). PowerShell runs in-process through PsProxy.dll and an internal runspace, so powershell.exe is never launched. A Cloudflare Worker (g-prx.itugegape524.workers.dev) acts as a fallback relay to api.github.com. GitHub credentials are rotated hourly via specially formatted "magic comments" in issue comments of the public Microsoft/vscode repository. A mutex of the form Global\[SHA256("GSC" + victim_id)] gates execution. Post-compromise activity included credential theft through PowerShell and exfiltration of at least 1 GB from the Kurdish government cloud environment, with results staged in the myCode repository.
Attribution (Dream Research): medium-to-high confidence that DarkBlinders overlaps UNC5795 and Dust Specter (HTTPService.dll/HTTPApi.dll mapped to SHELBYLOADER/SHELBYC2; GHOSTFORM/TREEWORLD sample matches); medium confidence that UNC5795 relates to UNC5187 via shared infrastructure (89.46.233.239) with a possible APT34 placement. Supporting but non-definitive Iranian indicators are ParsVDS nameserver use, a first check-in from a VM with a Persian keyboard layout, and Iranian hosting associations. The hunt skeleton referred to UNC1587; the primary-source extraction cites UNC5187, which is used here. Group-IB separately profiles a DarkBlinders actor (aviation and telecom targeting in the UAE and Iraqi Kurdistan, SHELBYLOADER/SHELBYC2, Stark Industries hosting, Peaky Blinders naming) with low-confidence Iran-nexus; its profile does not itself mention StarkMeet. Peaky Blinders theming recurs in GitHub accounts, infrastructure and a PDB path. Secondary reporting (GBHackers, Cyberpress) repeats the Dream findings.
MITRE ATT&CK techniques used in TL-2026-3223
Command and Control
T1008 Fallback Channels; T1102.002 Bidirectional Communication; T1573.001 Symmetric Cryptography
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Collection
Persistence
T1547.001 Registry Run Keys / Startup Folder
Initial Access
Exfiltration
T1567.001 Exfiltration to Code Repository
stealth
Resource Development
T1583.001 Domains; T1583.006 Web Services
Reconnaissance
Discovery
Affected products and versions in DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2
Remediation for DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2
Immediate actions
- Hunt for %LOCALAPPDATA%\Microsoft\RuntimeBroker containing RuntimeBroker.exe, RuntimeBroker.dll, RuntimeBrokerApi.dll, PsProxy.dll and RuntimeBroker.exe.config
- Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run value MicrosoftRuntime
- Block the listed phishing/StarkMeet domains and IPs and the Cloudflare Worker relay at DNS, proxy and email gateways
- Search proxy/EDR telemetry for non-browser, non-developer processes calling api.github.com, especially the PeakyBlindersTeam account and myLic/myCode repositories
- Reset credentials and revoke sessions for any user who entered credentials on lookalike OWA or cloud-drive pages; review cloud audit logs for bulk downloads
Workarounds
- Block execution from user-writable paths via application control (WDAC/AppLocker) for renamed signed binaries outside their expected directories
- Deny installation of unsigned Inno Setup installers from user downloads
Longer-term hardening
- Alert on .NET AppDomainManager hijacking (.config files with appDomainManagerAssembly/appDomainManagerType next to renamed signed binaries)
- Restrict outbound GitHub API access to approved processes and accounts
- Monitor in-process PowerShell hosting (System.Management.Automation loaded by non-PowerShell processes)
- Train staff on fake meeting-client and webmail-lure social engineering; enforce phishing-resistant MFA
Timeline of DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2
- Group-IB reports the DarkBlinders actor active since approximately September 2024 (SHELBYLOADER/SHELBYC2, Peaky Blinders-themed GitHub C2).
- Approximate start of the stable SSH host key on 89.46.233.239, the infrastructure shared between UNC5187 and UNC5795 (observed through October 2026).
- PeakyBlindersTM GitHub account created, one of several historical campaign-wave accounts (alongside johnshelllby, arturshellby, GreenBeret0 and peakyblinders-team).
- 77.223.215.140 (German multi-service resolver for campaign domains) first observed in the Dream timeline.
- 194.62.249.19 (UK, Google/Meet lookalike domains) first observed.
- 194.62.249.114 first observed hosting webmail lures; Dream dates the current campaign wave to August-October 2026.
- 89.125.209.80 begins hosting starkmeet.com, delivering the StarkMeet decoy installer.
- Last-observed date for the phishing IPs 194.62.249.19, 194.62.249.114 and 77.223.215.140 in the Dream report.
- Dream Research Labs publishes 'DarkBlinders: Inside An Active Espionage Campaign'; indicators submitted to ARPSyndicate/encryptlayer-intelligence PR #8.
- GBHackers and Cyberpress report the campaign; it remains active at publication.
Sources cited for DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2
- Dream Research Labs - DarkBlinders: Inside An Active Espionage Campaign
- GBHackers - DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data
- Cyberpress - DarkBlinders Hackers Use Fake Meeting App and GitHub Backdoor to Spy on Government Targets
- ARPSyndicate/encryptlayer-intelligence PR #8 - DarkBlinders phishing and C2 indicators
- Group-IB - DarkBlinders APT: Aviation & Telecom Espionage in UAE (actor profile)
- MITRE ATT&CK T1574.014 - Hijack Execution Flow: AppDomainManager
Detection coverage for TL-2026-3223
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3223 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.