Wire

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

News Plus

Welcome, one more step

The cross-newsroom layer: who covered a story, who didn’t, and how each one worded it. Plus your own news, on every device.

Follow your news

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email

See the coverage

  • Headlines side by side
  • Who reported first
  • Every newsroom clip, from every platform
  • Every newsroom photo on a story

Go deeper

  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Wire

Free stays free: the live wire, Not Everywhere, the brief, five follows and five Duki questions a day.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

News Plus · Ask Duki

Keep asking Duki

A free account gets five questions a day. News Plus lifts the daily limit.

Also in News Plus

  • The whole archive
  • Headlines side by side
  • Who reported first
  • The Desk, every hour
N12Security

Iranian Hackers Impersonate Dubai Air To Target Sensitive Infrastructure

Translated & summarized from N12 by baba

CenterNeutral tone

Hebrew · 2 newsrooms covering

Iranian hackers conducted a cyberespionage campaign called "Blinder Tunnel," impersonating Dubai Airports to target engineers with fake job offers and malicious code. The campaign, which began in late 2025, used "Peaky Blinders" themes and exploited Visual Studio to deploy malware. Targets included critical infrastructure in Iraq, Israel, and the UAE, though successful breaches remain unconfirmed.

The story in 6 lines · by baba

  • Iranian hackers ran the "Blinder Tunnel" cyber campaign, impersonating Dubai Airports to target engineers.
  • The campaign used fake job offers and malicious Visual Studio projects to deploy malware.
  • The attackers leveraged "Peaky Blinders" themes and GitHub for their infrastructure.
  • Targets included critical infrastructure in Iraq, Israel, and the United Arab Emirates.
  • Palo Alto Networks researchers uncovered the campaign and noted similarities to previous Iranian operations.
  • GitHub has removed the infrastructure used in the "Blinder Tunnel" campaign.

Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered a sophisticated cyberespionage campaign, dubbed "Blinder Tunnel," attributed to actors with ties to the Iranian regime. The campaign, which began preparations in November 2025 and escalated in March 2026, targeted engineers by impersonating IT managers from Dubai Airports and offering fake job opportunities. The initial phase involved creating a convincing fake recruitment portal to build trust before deploying malicious code.

In April 2026, the attackers sent a fake software developer test, a Visual Studio project designed to exploit a vulnerability in the development environment itself. The malware, identified as ShelbyLoader V2, was activated upon loading the project, even before compilation. It utilized legitimate Microsoft tools and GitHub for command and control, with a backup mechanism involving encrypted responses in GitHub Issues to retrieve alternative C2 addresses.

The campaign's infrastructure showed clear thematic links to the popular series "Peaky Blinders," with GitHub repositories named after characters and the theme song uploaded. Analysis of an audio file's metadata pointed to an Iranian music download site, suggesting an Iranian origin for the file. Further investigation linked the campaign's infrastructure to an Iranian internet provider and a tunneling server in Germany, which was also connected to a phishing campaign targeting Israel in May and June 2026.

This phishing campaign involved a fake Google Drive service offering a "War Unpublished Documents" download, leading to a fraudulent Google login page to steal credentials. Google confirmed no breach and blocked the malicious domains. The researchers noted similarities to previous campaigns, such as "The Shelby Strategy," and Iranian groups like Screening Serpens and Agent Serpens, known for similar recruitment scams and GitHub usage. The targets were critical infrastructure in Iraq, the UAE, and Israel, though Palo Alto Networks could not confirm successful breaches in Iraq or credential theft from the Israeli target at the time of reporting. GitHub has since removed the campaign's infrastructure.

N12Centre · Neve Ilan

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

News Plus · Follows

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like, with alerts for each in the app.

Your follows5 of 5 on the free plan
Or swap one out in Following

Also in News Plus

  • Alerts for what you follow
  • Hide read stories
  • The daily brief by email
  • Your reading diet

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

News Plus · Follows

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like, with alerts for each in the app.

Your follows5 of 5 on the free plan
Or swap one out in Following

Also in News Plus

  • Alerts for what you follow
  • Hide read stories
  • The daily brief by email
  • Your reading diet

Mentioned

Full coverage · 3 outlets
First: N12 · 22h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Open the Wire