Wire

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

News Plus

Welcome, one more step

The cross-newsroom layer: who covered a story, who didn’t, and how each one worded it. Plus your own news, on every device.

Follow your news

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email

See the coverage

  • Headlines side by side
  • Who reported first
  • Every newsroom clip, from every platform
  • Every newsroom photo on a story

Go deeper

  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Wire

Free stays free: the live wire, Not Everywhere, the brief, five follows and five Duki questions a day.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

News Plus · Ask Duki

Keep asking Duki

A free account gets five questions a day. News Plus lifts the daily limit.

Also in News Plus

  • The whole archive
  • Headlines side by side
  • Who reported first
  • The Desk, every hour
MakoSecurity

Iranian Hackers Impersonate Dubai Air To Target Sensitive Infrastructure

Translated & summarized from Mako by baba

CenterCharged tone

Hebrew · 2 newsrooms covering

Iranian hackers conducted a cyberespionage campaign called "Blinder Tunnel," impersonating Dubai Airports to target engineers in Iraq, Israel, and the UAE. The operation involved fake job offers and malicious code delivered via Visual Studio, aiming to infiltrate critical infrastructure. Researchers traced the campaign's infrastructure to Iran, and GitHub has removed the associated repositories. It is currently unconfirmed if the attacks in Iraq were successful or if Israeli targets had credentials stolen.

The story in 6 lines · by baba

  • Iranian hackers ran the "Blinder Tunnel" campaign, impersonating Dubai Airports to target engineers.
  • The campaign aimed to infiltrate critical infrastructure in Iraq, Israel, and the UAE.
  • Attackers used fake job offers and malicious code within a Visual Studio project to gain access.
  • The malware deployed ShelbyLoader V2 and used GitHub for command and control infrastructure.
  • Branding from the TV series "Peaky Blinders" was used, aiding researchers in tracing the attack to Iran.
  • A related phishing campaign targeted an Israeli entity using a fake Google Drive service.

Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered a sophisticated cyberespionage campaign, dubbed "Blinder Tunnel," attributed to actors with ties to the Iranian regime. The campaign targeted engineers by impersonating IT managers from Dubai Airports, offering fake job opportunities as a lure. The operation, which began preparations in November 2025, aimed to infiltrate critical infrastructure in Iraq, Israel, and the United Arab Emirates.

The initial phase involved sending a fake recruitment file, "Dubai Airport Careers," to potential victims, leading them to a fraudulent career portal. This stage was designed to build trust without deploying malware. In April 2026, the attackers escalated by sending a malicious Visual Studio project disguised as a software developer test. This project contained a hidden payload that executed when the code was loaded into Visual Studio, even before compilation.

The malware utilized a technique called AppDomainManager and DLL sideloading to deploy a payload named ShelbyLoader V2. It also leveraged a renamed Microsoft file, RuntimeBroker.exe, to execute malicious components. The attackers used GitHub for command and control, employing AES-256 encryption keys and a backup method of retrieving alternative C2 addresses from encrypted comments in GitHub Issues. GitHub has since removed the infrastructure used in the campaign.

Further stages involved PsProxy.dll for in-memory PowerShell command execution and Blackwood for tunneling traffic into victim networks via a SOCKS5 proxy. The attackers also adopted branding from the TV series "Peaky Blinders," naming GitHub repositories and files after characters and using the show's theme song. This branding, particularly an audio file's metadata, helped researchers trace infrastructure back to Iran, including an IP address linked to an Iranian ISP and a tunneling server in Germany associated with Persian-language domains.

The same infrastructure was linked to a phishing campaign against an Israeli target in May and June 2026, which used a fake Google Drive service to steal credentials. Google confirmed no breach and blocked the fraudulent domains. Palo Alto Networks suggests this campaign may be a continuation of previous operations, like "The Shelby Strategy," and notes similarities with other Iranian hacking groups. While the attackers targeted telecom, aviation, and infrastructure sectors, it remains unconfirmed whether the breaches in Iraq were successful or if credentials were stolen from the Israeli target.

MakoCentre · Neve Ilan

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

News Plus · Follows

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like, with alerts for each in the app.

Your follows5 of 5 on the free plan
Or swap one out in Following

Also in News Plus

  • Alerts for what you follow
  • Hide read stories
  • The daily brief by email
  • Your reading diet

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

News Plus · Follows

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like, with alerts for each in the app.

Your follows5 of 5 on the free plan
Or swap one out in Following

Also in News Plus

  • Alerts for what you follow
  • Hide read stories
  • The daily brief by email
  • Your reading diet

Mentioned

Full coverage · 3 outlets
First: Mako · 21h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Open the Wire