Iranian Hackers Impersonate Dubai Air To Target Sensitive Infrastructure
Translated & summarized from Mako by baba
Iranian hackers conducted a cyberespionage campaign called "Blinder Tunnel," impersonating Dubai Airports to target engineers in Iraq, Israel, and the UAE. The operation involved fake job offers and malicious code delivered via Visual Studio, aiming to infiltrate critical infrastructure. Researchers traced the campaign's infrastructure to Iran, and GitHub has removed the associated repositories. It is currently unconfirmed if the attacks in Iraq were successful or if Israeli targets had credentials stolen.
The story in 6 lines · by baba
- Iranian hackers ran the "Blinder Tunnel" campaign, impersonating Dubai Airports to target engineers.
- The campaign aimed to infiltrate critical infrastructure in Iraq, Israel, and the UAE.
- Attackers used fake job offers and malicious code within a Visual Studio project to gain access.
- The malware deployed ShelbyLoader V2 and used GitHub for command and control infrastructure.
- Branding from the TV series "Peaky Blinders" was used, aiding researchers in tracing the attack to Iran.
- A related phishing campaign targeted an Israeli entity using a fake Google Drive service.
Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered a sophisticated cyberespionage campaign, dubbed "Blinder Tunnel," attributed to actors with ties to the Iranian regime. The campaign targeted engineers by impersonating IT managers from Dubai Airports, offering fake job opportunities as a lure. The operation, which began preparations in November 2025, aimed to infiltrate critical infrastructure in Iraq, Israel, and the United Arab Emirates.
The initial phase involved sending a fake recruitment file, "Dubai Airport Careers," to potential victims, leading them to a fraudulent career portal. This stage was designed to build trust without deploying malware. In April 2026, the attackers escalated by sending a malicious Visual Studio project disguised as a software developer test. This project contained a hidden payload that executed when the code was loaded into Visual Studio, even before compilation.
The malware utilized a technique called AppDomainManager and DLL sideloading to deploy a payload named ShelbyLoader V2. It also leveraged a renamed Microsoft file, RuntimeBroker.exe, to execute malicious components. The attackers used GitHub for command and control, employing AES-256 encryption keys and a backup method of retrieving alternative C2 addresses from encrypted comments in GitHub Issues. GitHub has since removed the infrastructure used in the campaign.
Further stages involved PsProxy.dll for in-memory PowerShell command execution and Blackwood for tunneling traffic into victim networks via a SOCKS5 proxy. The attackers also adopted branding from the TV series "Peaky Blinders," naming GitHub repositories and files after characters and using the show's theme song. This branding, particularly an audio file's metadata, helped researchers trace infrastructure back to Iran, including an IP address linked to an Iranian ISP and a tunneling server in Germany associated with Persian-language domains.
The same infrastructure was linked to a phishing campaign against an Israeli target in May and June 2026, which used a fake Google Drive service to steal credentials. Google confirmed no breach and blocked the fraudulent domains. Palo Alto Networks suggests this campaign may be a continuation of previous operations, like "The Shelby Strategy," and notes similarities with other Iranian hacking groups. While the attackers targeted telecom, aviation, and infrastructure sectors, it remains unconfirmed whether the breaches in Iraq were successful or if credentials were stolen from the Israeli target.
Mentioned