Threat reportAPTTL-2026-3223

DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 to Deploy RuntimeBroker Backdoor Against Government Targets

highACTIVE

DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 (TL-2026-3223), also tracked as StarkMeet campaign, is a high-severity advanced persistent threat campaign, first published 2026-10-10. It is attributed to DarkBlinders (Iran) with medium confidence, affects Microsoft Windows (endpoints executing the StarkMeet installer), maps to 17 MITRE ATT&CK techniques (T1008, T1036.005, T1059.001), and is covered by 9 detection rules and 34 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
1DarkBlinders
Detection rules
9SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-3223

Threat ID
TL-2026-3223
Also known as
StarkMeet campaign, PeakyBlinders
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
DarkBlinders
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
government administration, it - security, telecoms, aviation
Target regions
Middle East, iraq, israel, kuwait, GCC, united arab emirates
Detection rules
9
Indicators of compromise
34

How DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 works

DarkBlinders (assessed Iran-nexus; overlaps UNC5795 / Dust Specter) lures victims with webmail and cloud-drive phishing pages and a fake video-meeting client, StarkMeet, that installs a .NET AppDomainManager backdoor (RuntimeBroker.dll / RuntimeBrokerApi.dll / PsProxy.dll) controlled through GitHub repositories. Two confirmed victims: an Israeli security-sector individual and a Kurdistan Regional Government cloud environment (1+ GB exfiltrated).

Dream Research Labs (report published 2026-10-08, "DarkBlinders: Inside An Active Espionage Campaign") documents a campaign observed August-October 2026 and still active at publication. The operator combines credential-phishing pages that impersonate Outlook Web Access/webmail for Kuwait's Ministry of Foreign Affairs (mfakuwait lookalikes), the GCC Secretariat General (gcc-sg lookalikes) and Kurdistan Regional Government services (krgcloud, moelcloud), fraudulent cloud-drive and meeting pages (msonedrive, googedrive, drive-g, googemeet), and a fake meeting client named StarkMeet. The initial delivery route to the confirmed victims has not been confirmed in the sources.

The StarkMeet package (StarkMeet.zip) contains an unsigned Inno Setup installer presenting version 3.2 of a .NET decoy with Stark Industries branding. The decoy shows local camera, microphone and screen previews, but joining a meeting always returns a fixed connection error. The installer drops components into %LOCALAPPDATA%\Microsoft\RuntimeBroker so that the implant survives removal of the visible application. A signed Microsoft vshost.exe is renamed RuntimeBroker.exe and loads RuntimeBroker.dll through an AppDomainManager mechanism (a .config-driven .NET loading technique). Persistence is the HKCU Run value MicrosoftRuntime.

RuntimeBroker.dll is a loader. It uses an embedded GitHub token to register each infected host in the PeakyBlindersTeam/myLic repository, reporting username, machine name, domain, keyboard layout, persistence status and anti-analysis findings. Operators review this metadata and selectively activate victims: roughly 10 initial registrations were recovered and only 2 progressed to second-stage deployment. The second stage, RuntimeBrokerApi.dll, is decrypted with AES-256-CBC (PKCS7) using a key derived as SHA-256 of a license string, with the IV taken from the first 16 bytes of the key. It polls the myCode repository about every 63 seconds for commands (/up, /dl, /de, /rate, plus PowerShell execution). PowerShell runs in-process through PsProxy.dll and an internal runspace, so powershell.exe is never launched. A Cloudflare Worker (g-prx.itugegape524.workers.dev) acts as a fallback relay to api.github.com. GitHub credentials are rotated hourly via specially formatted "magic comments" in issue comments of the public Microsoft/vscode repository. A mutex of the form Global\[SHA256("GSC" + victim_id)] gates execution. Post-compromise activity included credential theft through PowerShell and exfiltration of at least 1 GB from the Kurdish government cloud environment, with results staged in the myCode repository.

Attribution (Dream Research): medium-to-high confidence that DarkBlinders overlaps UNC5795 and Dust Specter (HTTPService.dll/HTTPApi.dll mapped to SHELBYLOADER/SHELBYC2; GHOSTFORM/TREEWORLD sample matches); medium confidence that UNC5795 relates to UNC5187 via shared infrastructure (89.46.233.239) with a possible APT34 placement. Supporting but non-definitive Iranian indicators are ParsVDS nameserver use, a first check-in from a VM with a Persian keyboard layout, and Iranian hosting associations. The hunt skeleton referred to UNC1587; the primary-source extraction cites UNC5187, which is used here. Group-IB separately profiles a DarkBlinders actor (aviation and telecom targeting in the UAE and Iraqi Kurdistan, SHELBYLOADER/SHELBYC2, Stark Industries hosting, Peaky Blinders naming) with low-confidence Iran-nexus; its profile does not itself mention StarkMeet. Peaky Blinders theming recurs in GitHub accounts, infrastructure and a PDB path. Secondary reporting (GBHackers, Cyberpress) repeats the Dream findings.

MITRE ATT&CK techniques used in TL-2026-3223

Command and Control

T1008 Fallback Channels; T1102.002 Bidirectional Communication; T1573.001 Symmetric Cryptography

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion

Execution

T1059.001 PowerShell; T1204.002 Malicious File

Collection

T1530 Data from Cloud Storage

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.002 Spearphishing Link

Exfiltration

T1567.001 Exfiltration to Code Repository

stealth

T1574.014 AppDomainManager

Resource Development

T1583.001 Domains; T1583.006 Web Services

Reconnaissance

T1598.003 Spearphishing Link

Discovery

T1614.001 System Language Discovery

Affected products and versions in DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2

  • Microsoft — Windows (endpoints executing the StarkMeet installer)
    Vulnerable versions: Not version-specific; social-engineering delivery
  • Microsoft — Outlook Web Access / webmail and cloud-drive services (impersonated by phishing pages)
    Vulnerable versions: Brand impersonation only; no product flaw

Remediation for DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2

Immediate actions

  • Hunt for %LOCALAPPDATA%\Microsoft\RuntimeBroker containing RuntimeBroker.exe, RuntimeBroker.dll, RuntimeBrokerApi.dll, PsProxy.dll and RuntimeBroker.exe.config
  • Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run value MicrosoftRuntime
  • Block the listed phishing/StarkMeet domains and IPs and the Cloudflare Worker relay at DNS, proxy and email gateways
  • Search proxy/EDR telemetry for non-browser, non-developer processes calling api.github.com, especially the PeakyBlindersTeam account and myLic/myCode repositories
  • Reset credentials and revoke sessions for any user who entered credentials on lookalike OWA or cloud-drive pages; review cloud audit logs for bulk downloads

Workarounds

  • Block execution from user-writable paths via application control (WDAC/AppLocker) for renamed signed binaries outside their expected directories
  • Deny installation of unsigned Inno Setup installers from user downloads

Longer-term hardening

  • Alert on .NET AppDomainManager hijacking (.config files with appDomainManagerAssembly/appDomainManagerType next to renamed signed binaries)
  • Restrict outbound GitHub API access to approved processes and accounts
  • Monitor in-process PowerShell hosting (System.Management.Automation loaded by non-PowerShell processes)
  • Train staff on fake meeting-client and webmail-lure social engineering; enforce phishing-resistant MFA

Timeline of DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2

  • Group-IB reports the DarkBlinders actor active since approximately September 2024 (SHELBYLOADER/SHELBYC2, Peaky Blinders-themed GitHub C2).
  • Approximate start of the stable SSH host key on 89.46.233.239, the infrastructure shared between UNC5187 and UNC5795 (observed through October 2026).
  • PeakyBlindersTM GitHub account created, one of several historical campaign-wave accounts (alongside johnshelllby, arturshellby, GreenBeret0 and peakyblinders-team).
  • 77.223.215.140 (German multi-service resolver for campaign domains) first observed in the Dream timeline.
  • 194.62.249.19 (UK, Google/Meet lookalike domains) first observed.
  • 194.62.249.114 first observed hosting webmail lures; Dream dates the current campaign wave to August-October 2026.
  • 89.125.209.80 begins hosting starkmeet.com, delivering the StarkMeet decoy installer.
  • Last-observed date for the phishing IPs 194.62.249.19, 194.62.249.114 and 77.223.215.140 in the Dream report.
  • Dream Research Labs publishes 'DarkBlinders: Inside An Active Espionage Campaign'; indicators submitted to ARPSyndicate/encryptlayer-intelligence PR #8.
  • GBHackers and Cyberpress report the campaign; it remains active at publication.

Sources cited for DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2

Detection coverage for TL-2026-3223

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3223 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats