# DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 to Deploy RuntimeBroker Backdoor Against Government Targets

> DarkBlinders (assessed Iran-nexus; overlaps UNC5795 / Dust Specter) lures victims with webmail and cloud-drive phishing pages and a fake video-meeting client, StarkMeet, that installs a .NET AppDomainManager backdoor (RuntimeBroker.dll / RuntimeBrokerApi.dll / PsProxy.dll) controlled through GitHub repositories. Two confirmed victims: an Israeli security-sector individual and a Kurdistan Regional Government cloud environment (1+ GB exfiltrated).

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3223
- **ID:** TL-2026-3223
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** DarkBlinders (Iran)
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Dream Research Labs (report published 2026-10-08, "DarkBlinders: Inside An Active Espionage Campaign") documents a campaign observed August-October 2026 and still active at publication. The operator combines credential-phishing pages that impersonate Outlook Web Access/webmail for Kuwait's Ministry of Foreign Affairs (mfakuwait lookalikes), the GCC Secretariat General (gcc-sg lookalikes) and Kurdistan Regional Government services (krgcloud, moelcloud), fraudulent cloud-drive and meeting pages (msonedrive, googedrive, drive-g, googemeet), and a fake meeting client named StarkMeet. The initial delivery route to the confirmed victims has not been confirmed in the sources.

The StarkMeet package (StarkMeet.zip) contains an unsigned Inno Setup installer presenting version 3.2 of a .NET decoy with Stark Industries branding. The decoy shows local camera, microphone and screen previews, but joining a meeting always returns a fixed connection error. The installer drops components into %LOCALAPPDATA%\Microsoft\RuntimeBroker so that the implant survives removal of the visible application. A signed Microsoft vshost.exe is renamed RuntimeBroker.exe and loads RuntimeBroker.dll through an AppDomainManager mechanism (a .config-driven .NET loading technique). Persistence is the HKCU Run value MicrosoftRuntime.

RuntimeBroker.dll is a loader. It uses an embedded GitHub token to register each infected host in the PeakyBlindersTeam/myLic repository, reporting username, machine name, domain, keyboard layout, persistence status and anti-analysis findings. Operators review this metadata and selectively activate victims: roughly 10 initial registrations were recovered and only 2 progressed to second-stage deployment. The second stage, RuntimeBrokerApi.dll, is decrypted with AES-256-CBC (PKCS7) using a key derived as SHA-256 of a license string, with the IV taken from the first 16 bytes of the key. It polls the myCode repository about every 63 seconds for commands (/up, /dl, /de, /rate, plus PowerShell execution). PowerShell runs in-process through PsProxy.dll and an internal runspace, so powershell.exe is never launched. A Cloudflare Worker (g-prx.itugegape524.workers.dev) acts as a fallback relay to api.github.com. GitHub credentials are rotated hourly via specially formatted "magic comments" in issue comments of the public Microsoft/vscode repository. A mutex of the form Global\[SHA256("GSC" + victim_id)] gates execution. Post-compromise activity included credential theft through PowerShell and exfiltration of at least 1 GB from the Kurdish government cloud environment, with results staged in the myCode repository.

Attribution (Dream Research): medium-to-high confidence that DarkBlinders overlaps UNC5795 and Dust Specter (HTTPService.dll/HTTPApi.dll mapped to SHELBYLOADER/SHELBYC2; GHOSTFORM/TREEWORLD sample matches); medium confidence that UNC5795 relates to UNC5187 via shared infrastructure (89.46.233.239) with a possible APT34 placement. Supporting but non-definitive Iranian indicators are ParsVDS nameserver use, a first check-in from a VM with a Persian keyboard layout, and Iranian hosting associations. The hunt skeleton referred to UNC1587; the primary-source extraction cites UNC5187, which is used here. Group-IB separately profiles a DarkBlinders actor (aviation and telecom targeting in the UAE and Iraqi Kurdistan, SHELBYLOADER/SHELBYC2, Stark Industries hosting, Peaky Blinders naming) with low-confidence Iran-nexus; its profile does not itself mention StarkMeet. Peaky Blinders theming recurs in GitHub accounts, infrastructure and a PDB path. Secondary reporting (GBHackers, Cyberpress) repeats the Dream findings.

## MITRE ATT&CK

- T1583.001 Domains
- T1583.006 Web Services
- T1598.003 Spearphishing Link
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1547.001 Registry Run Keys / Startup Folder
- T1574.014 AppDomainManager
- T1036.005 Match Legitimate Resource Name or Location
- T1497 Virtualization/Sandbox Evasion
- T1480 Execution Guardrails
- T1614.001 System Language Discovery
- T1530 Data from Cloud Storage
- T1102.002 Bidirectional Communication
- T1573.001 Symmetric Cryptography
- T1008 Fallback Channels
- T1567.001 Exfiltration to Code Repository

## Sources

- [Dream Research Labs - DarkBlinders: Inside An Active Espionage Campaign](https://www.dreamgroup.com/blog/darkblinders-inside-an-active-espionage-campaign)
- [GBHackers - DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data](https://gbhackers.com/darkblinders-hackers-use-fake-meeting-app/)
- [Cyberpress - DarkBlinders Hackers Use Fake Meeting App and GitHub Backdoor to Spy on Government Targets](https://cyberpress.org/darkblinders-hackers-use-fake-meeting-app-and-github-backdoor/)
- [ARPSyndicate/encryptlayer-intelligence PR #8 - DarkBlinders phishing and C2 indicators](https://github.com/ARPSyndicate/encryptlayer-intelligence/pull/8)
- [Group-IB - DarkBlinders APT: Aviation & Telecom Espionage in UAE (actor profile)](https://www.group-ib.com/masked-actors/darkblinders/)
- [MITRE ATT&CK T1574.014 - Hijack Execution Flow: AppDomainManager](https://attack.mitre.org/techniques/T1574/014/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3223
