Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
Key Takeaways Iranian state-sponsored threat actors are targeting Iraqi critical infrastructure. The attack leverages a sophisticated social engineering scheme posing as a Dubai Airports coding test....
Key Takeaways
- Iranian state-sponsored threat actors are targeting Iraqi critical infrastructure.
- The attack leverages a sophisticated social engineering scheme posing as a Dubai Airports coding test.
- The campaign, dubbed Blinder Tunnel, establishes remote access, persistence, and network tunneling capabilities.
- The attackers exploit trusted developer tools and environments, making detection challenging.
- No compromise of Dubai Airports systems was found; the name was used for impersonation.
Iranian state-aligned cyber operatives have launched a sophisticated campaign, dubbed “Blinder Tunnel,” targeting critical infrastructure in Iraq. The attack vector involves a deceptive recruitment process for Dubai Airports, culminating in a booby-trapped coding test designed to establish persistent remote access and network tunneling capabilities within victim environments.
Table Of Content
This operation transforms a seemingly innocuous developer task into a stealthy conduit for long-term infiltration. According to a recent report, the operation was meticulously planned as early as November 2025 and initiated its attack phase in March 2026, targeting a software engineer likely based in Iraq.
The attackers first presented victims with a highly convincing offline careers portal, followed by a personalized Visual Studio project. This project was framed as an at-home coding assessment for a development position. Researchers from Unit 42, who identified this activity as CL-STA-1178, have assessed with high confidence that this campaign originates from an Iranian-nexus threat actor. The group impersonated IT staff from Dubai Airports, though investigators found no evidence of any compromise or vulnerability within Dubai Airports’ actual systems.
This incident underscores the increasing value of developer environments as targets. A seemingly benign coding project can become a critical vulnerability, as trusted build tools can execute malicious instructions before a developer even writes or compiles any code.
Palo Alto Networks said in a report that the threat actors ingeniously utilized cloud services to obscure their command-and-control traffic, making it harder to detect and trace their activities.
Iranian Hackers Use Fake Dubai Airports Coding Test
The initial phase of the attack, launched in late March, involved an Inno Setup application titled “Dubai Airport Careers.” This application presented a localized, simulated careers website. Victims were prompted to enter credentials supposedly provided by the recruiters and complete a 10-question HR form. This portal was designed to build trust; it did not immediately steal data or deploy malware, a calculated move to set the stage for subsequent, more malicious steps.
The next stage involved an archive named “DubaiAirport_Carrers_IT_Test.zip.” This archive contained a Readme.md file with instructions for the target, asking them to open a C# Flight Management System project and correct a simple loop error. This tailored lure aligns with known Iranian fake recruitment tactics, where job opportunities are exploited to gather intelligence or gain unauthorized access.
Merely opening the provided Visual Studio project was sufficient to trigger the attack chain. A weaponized “FlightManager.csproj” file leveraged Visual Studio’s standard background evaluation process. This initiated the creation of a deceptive “RuntimeBrokers” folder within local application data and executed “RuntimeBroker.exe” even before the developer had compiled the project.
Subsequently, the attackers modified “RuntimeBroker.exe.config” to hijack AppDomainManager. This technique forces the attacker’s code to execute prior to the legitimate host application. The configuration also deliberately disabled Event Tracing for Windows, a move designed to reduce the telemetry available to defenders for detecting suspicious .NET activity. Similar AppDomainManager hijacking methods have been observed in other Iran-linked intrusion sets.
The final step in the initial access phase involved DLL sideloading. A renamed, legitimate Visual Studio hosting process loaded “RuntimeBroker.dll,” identified as the ShelbyLoader V2 loader. Security teams are advised to investigate signed binaries that load unfamiliar DLLs from unusual directories and to monitor for anomalous msbuild.exe activity, unexpected developer projects, and modifications to .NET configuration files.
GitHub C2 and Tunneling Tool
ShelbyLoader V2 established persistence by creating a registry Run value, profiled the victim host, and communicated with the attacker’s infrastructure via GitHub’s API. It uploaded a unique machine fingerprint and retrieved tasking. In the event of primary communication failure, it possessed a fallback mechanism to retrieve encrypted data hidden within GitHub issue comments. GitHub has since removed the infrastructure identified during the investigation.
The loader then decrypted and executed the ShelbyC2 V2 backdoor, which utilized PsProxy.dll to run commands through the PowerShell engine without directly launching “PowerShell.exe.” Additionally, the attackers staged Blackwood, a memory-resident wrapper for Chisel. Blackwood is capable of establishing encrypted tunnels and a reverse SOCKS proxy, enabling the operators to deepen their penetration into the compromised network. This tunneling approach mirrors methods seen in other intrusion campaigns that leverage Chisel for covert communications.
Researchers linked this activity cluster to Iran based on infrastructure analysis, observed targeting patterns, and an operational error: metadata within an audio file referenced “MusicDel[.]ir.” Furthermore, investigators discovered related credential-harvesting infrastructure in May and June 2026, explicitly targeting an Israeli entity.
What You Should Do
- Verify Job-Related Communications: Always independently verify job offers and recruitment processes through official, public channels of the purported employer, not through links or contacts provided in the initial outreach.
- Isolate Suspicious Systems: Immediately isolate any system that displays suspicious activity related to developer projects or unexpected software installations.
- Reset Exposed Credentials: If any credentials were entered into a suspicious portal, reset them across all platforms immediately.
- Review GitHub API Activity: Monitor and review GitHub API activity within your organization for any patterns that deviate from normal development workflows.
- Implement Phishing-Resistant MFA: Deploy and enforce phishing-resistant multi-factor authentication (MFA) across all accounts, especially for critical systems and developer environments.
- Verify URLs: Before entering any credentials, meticulously verify the destination URL to ensure it belongs to the legitimate service.
- Monitor for Unusual DLL Loading: Implement monitoring for signed binaries loading unfamiliar DLLs from non-standard system directories.
- Alert on .NET Configuration Changes: Configure alerts for unexpected changes to .NET configuration files and unusual msbuild.exe activity.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA256 | 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 |
DubaiAirport_Carrers_IT_Test.zip, initial malicious archive |
| SHA256 | f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 |
FlightManager.csproj, weaponized Visual Studio project file |
| SHA256 | 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 |
RuntimeBroker.dll, primary RAT loader |
| SHA256 | 3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 |
PsProxy.dll, in-memory PowerShell execution engine |
| SHA256 | 76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e |
Blackwood.dll, custom Chisel tunneling wrapper |
| SHA256 | d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 |
Blackwood.dll.conf, contacting 91.107.156[.]29 |
| SHA256 | f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd |
Blackwood archive, contacting 65.109.214[.]145 |
| SHA256 | 7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875 |
Blackwood archive, contacting 87.248.129[.]239 |
| IP Address | 91.107.156[.]29 |
Blackwood tunneling endpoint |
| IP Address | 87.248.129[.]239 |
Infrastructure linked to Blackwood |
| IP Address | 65.109.214[.]145 |
Credential-harvesting and Blackwood infrastructure |
| IP Address | 38.180.136[.]127 |
Earlier phishing staging infrastructure |
| Domain | cloud.g-drive[.]cam |
Phishing domain |
| Domain | googeldrive[.]cam |
Phishing domain |
| Domain | drivegoogel[.]cam |
Phishing domain |
| Domain | googelmeet[.]online |
Phishing domain |
| Domain | meetonline[.]cam |
Phishing domain |
| Domain | asdfafadafg[.]online |
Phishing staging domain |
| Registry Key | HKCUSOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftRuntime |
ShelbyLoader V2 persistence location |
| GitHub C2 | hxxps[:]//github[.]com/peakyblinders-tm |
GitHub command-and-control infrastructure |
| GitHub C2 | hxxps[:]//github[.]com/GreenBeret0 |
GitHub dead-drop resolution testing infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.