Iranian Hackers Impersonate Dubai Air To Target Sensitive Infrastructure
Translated & summarized from N12 by baba
Iranian hackers conducted a cyberespionage campaign called "Blinder Tunnel," impersonating Dubai Airports to target engineers with fake job offers and malicious code. The campaign, which began in late 2025, used "Peaky Blinders" themes and exploited Visual Studio to deploy malware. Targets included critical infrastructure in Iraq, Israel, and the UAE, though successful breaches remain unconfirmed.
The story in 6 lines · by baba
- Iranian hackers ran the "Blinder Tunnel" cyber campaign, impersonating Dubai Airports to target engineers.
- The campaign used fake job offers and malicious Visual Studio projects to deploy malware.
- The attackers leveraged "Peaky Blinders" themes and GitHub for their infrastructure.
- Targets included critical infrastructure in Iraq, Israel, and the United Arab Emirates.
- Palo Alto Networks researchers uncovered the campaign and noted similarities to previous Iranian operations.
- GitHub has removed the infrastructure used in the "Blinder Tunnel" campaign.
Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered a sophisticated cyberespionage campaign, dubbed "Blinder Tunnel," attributed to actors with ties to the Iranian regime. The campaign, which began preparations in November 2025 and escalated in March 2026, targeted engineers by impersonating IT managers from Dubai Airports and offering fake job opportunities. The initial phase involved creating a convincing fake recruitment portal to build trust before deploying malicious code.
In April 2026, the attackers sent a fake software developer test, a Visual Studio project designed to exploit a vulnerability in the development environment itself. The malware, identified as ShelbyLoader V2, was activated upon loading the project, even before compilation. It utilized legitimate Microsoft tools and GitHub for command and control, with a backup mechanism involving encrypted responses in GitHub Issues to retrieve alternative C2 addresses.
The campaign's infrastructure showed clear thematic links to the popular series "Peaky Blinders," with GitHub repositories named after characters and the theme song uploaded. Analysis of an audio file's metadata pointed to an Iranian music download site, suggesting an Iranian origin for the file. Further investigation linked the campaign's infrastructure to an Iranian internet provider and a tunneling server in Germany, which was also connected to a phishing campaign targeting Israel in May and June 2026.
This phishing campaign involved a fake Google Drive service offering a "War Unpublished Documents" download, leading to a fraudulent Google login page to steal credentials. Google confirmed no breach and blocked the malicious domains. The researchers noted similarities to previous campaigns, such as "The Shelby Strategy," and Iranian groups like Screening Serpens and Agent Serpens, known for similar recruitment scams and GitHub usage. The targets were critical infrastructure in Iraq, the UAE, and Israel, though Palo Alto Networks could not confirm successful breaches in Iraq or credential theft from the Israeli target at the time of reporting. GitHub has since removed the campaign's infrastructure.
Mentioned