Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
ASOS Hacked: App Users Receive Malicious Notifications
October 6, 2026
SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring
October 6, 2026
Critical GitHub Copilot CLI Bug Exposes Developer Secrets via Prompt Injection
October 6, 2026
Home/CyberSecurity News/Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
CyberSecurity News

Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test

Key Takeaways Iranian state-sponsored threat actors are targeting Iraqi critical infrastructure. The attack leverages a sophisticated social engineering scheme posing as a Dubai Airports coding test....

Emy Elsamnoudy
Emy Elsamnoudy
October 6, 2026 5 Min Read
2 0

Key Takeaways

  • Iranian state-sponsored threat actors are targeting Iraqi critical infrastructure.
  • The attack leverages a sophisticated social engineering scheme posing as a Dubai Airports coding test.
  • The campaign, dubbed Blinder Tunnel, establishes remote access, persistence, and network tunneling capabilities.
  • The attackers exploit trusted developer tools and environments, making detection challenging.
  • No compromise of Dubai Airports systems was found; the name was used for impersonation.

Iranian state-aligned cyber operatives have launched a sophisticated campaign, dubbed “Blinder Tunnel,” targeting critical infrastructure in Iraq. The attack vector involves a deceptive recruitment process for Dubai Airports, culminating in a booby-trapped coding test designed to establish persistent remote access and network tunneling capabilities within victim environments.

Table Of Content

  • Key Takeaways
  • Iranian Hackers Use Fake Dubai Airports Coding Test
  • GitHub C2 and Tunneling Tool
  • What You Should Do

This operation transforms a seemingly innocuous developer task into a stealthy conduit for long-term infiltration. According to a recent report, the operation was meticulously planned as early as November 2025 and initiated its attack phase in March 2026, targeting a software engineer likely based in Iraq.

The attackers first presented victims with a highly convincing offline careers portal, followed by a personalized Visual Studio project. This project was framed as an at-home coding assessment for a development position. Researchers from Unit 42, who identified this activity as CL-STA-1178, have assessed with high confidence that this campaign originates from an Iranian-nexus threat actor. The group impersonated IT staff from Dubai Airports, though investigators found no evidence of any compromise or vulnerability within Dubai Airports’ actual systems.

This incident underscores the increasing value of developer environments as targets. A seemingly benign coding project can become a critical vulnerability, as trusted build tools can execute malicious instructions before a developer even writes or compiles any code.

Palo Alto Networks said in a report that the threat actors ingeniously utilized cloud services to obscure their command-and-control traffic, making it harder to detect and trace their activities.

Iranian Hackers Use Fake Dubai Airports Coding Test

The initial phase of the attack, launched in late March, involved an Inno Setup application titled “Dubai Airport Careers.” This application presented a localized, simulated careers website. Victims were prompted to enter credentials supposedly provided by the recruiters and complete a 10-question HR form. This portal was designed to build trust; it did not immediately steal data or deploy malware, a calculated move to set the stage for subsequent, more malicious steps.

The next stage involved an archive named “DubaiAirport_Carrers_IT_Test.zip.” This archive contained a Readme.md file with instructions for the target, asking them to open a C# Flight Management System project and correct a simple loop error. This tailored lure aligns with known Iranian fake recruitment tactics, where job opportunities are exploited to gather intelligence or gain unauthorized access.

Merely opening the provided Visual Studio project was sufficient to trigger the attack chain. A weaponized “FlightManager.csproj” file leveraged Visual Studio’s standard background evaluation process. This initiated the creation of a deceptive “RuntimeBrokers” folder within local application data and executed “RuntimeBroker.exe” even before the developer had compiled the project.

Subsequently, the attackers modified “RuntimeBroker.exe.config” to hijack AppDomainManager. This technique forces the attacker’s code to execute prior to the legitimate host application. The configuration also deliberately disabled Event Tracing for Windows, a move designed to reduce the telemetry available to defenders for detecting suspicious .NET activity. Similar AppDomainManager hijacking methods have been observed in other Iran-linked intrusion sets.

The final step in the initial access phase involved DLL sideloading. A renamed, legitimate Visual Studio hosting process loaded “RuntimeBroker.dll,” identified as the ShelbyLoader V2 loader. Security teams are advised to investigate signed binaries that load unfamiliar DLLs from unusual directories and to monitor for anomalous msbuild.exe activity, unexpected developer projects, and modifications to .NET configuration files.

GitHub C2 and Tunneling Tool

ShelbyLoader V2 established persistence by creating a registry Run value, profiled the victim host, and communicated with the attacker’s infrastructure via GitHub’s API. It uploaded a unique machine fingerprint and retrieved tasking. In the event of primary communication failure, it possessed a fallback mechanism to retrieve encrypted data hidden within GitHub issue comments. GitHub has since removed the infrastructure identified during the investigation.

The loader then decrypted and executed the ShelbyC2 V2 backdoor, which utilized PsProxy.dll to run commands through the PowerShell engine without directly launching “PowerShell.exe.” Additionally, the attackers staged Blackwood, a memory-resident wrapper for Chisel. Blackwood is capable of establishing encrypted tunnels and a reverse SOCKS proxy, enabling the operators to deepen their penetration into the compromised network. This tunneling approach mirrors methods seen in other intrusion campaigns that leverage Chisel for covert communications.

Researchers linked this activity cluster to Iran based on infrastructure analysis, observed targeting patterns, and an operational error: metadata within an audio file referenced “MusicDel[.]ir.” Furthermore, investigators discovered related credential-harvesting infrastructure in May and June 2026, explicitly targeting an Israeli entity.

What You Should Do

  • Verify Job-Related Communications: Always independently verify job offers and recruitment processes through official, public channels of the purported employer, not through links or contacts provided in the initial outreach.
  • Isolate Suspicious Systems: Immediately isolate any system that displays suspicious activity related to developer projects or unexpected software installations.
  • Reset Exposed Credentials: If any credentials were entered into a suspicious portal, reset them across all platforms immediately.
  • Review GitHub API Activity: Monitor and review GitHub API activity within your organization for any patterns that deviate from normal development workflows.
  • Implement Phishing-Resistant MFA: Deploy and enforce phishing-resistant multi-factor authentication (MFA) across all accounts, especially for critical systems and developer environments.
  • Verify URLs: Before entering any credentials, meticulously verify the destination URL to ensure it belongs to the legitimate service.
  • Monitor for Unusual DLL Loading: Implement monitoring for signed binaries loading unfamiliar DLLs from non-standard system directories.
  • Alert on .NET Configuration Changes: Configure alerts for unexpected changes to .NET configuration files and unusual msbuild.exe activity.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA256 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 DubaiAirport_Carrers_IT_Test.zip, initial malicious archive
SHA256 f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 FlightManager.csproj, weaponized Visual Studio project file
SHA256 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 RuntimeBroker.dll, primary RAT loader
SHA256 3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 PsProxy.dll, in-memory PowerShell execution engine
SHA256 76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e Blackwood.dll, custom Chisel tunneling wrapper
SHA256 d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 Blackwood.dll.conf, contacting 91.107.156[.]29
SHA256 f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd Blackwood archive, contacting 65.109.214[.]145
SHA256 7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875 Blackwood archive, contacting 87.248.129[.]239
IP Address 91.107.156[.]29 Blackwood tunneling endpoint
IP Address 87.248.129[.]239 Infrastructure linked to Blackwood
IP Address 65.109.214[.]145 Credential-harvesting and Blackwood infrastructure
IP Address 38.180.136[.]127 Earlier phishing staging infrastructure
Domain cloud.g-drive[.]cam Phishing domain
Domain googeldrive[.]cam Phishing domain
Domain drivegoogel[.]cam Phishing domain
Domain googelmeet[.]online Phishing domain
Domain meetonline[.]cam Phishing domain
Domain asdfafadafg[.]online Phishing staging domain
Registry Key HKCUSOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftRuntime ShelbyLoader V2 persistence location
GitHub C2 hxxps[:]//github[.]com/peakyblinders-tm GitHub command-and-control infrastructure
GitHub C2 hxxps[:]//github[.]com/GreenBeret0 GitHub dead-drop resolution testing infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwarephishingSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks

Next Post

Ex-Engineer Jailed for Sabotaging Employer’s Windows Network

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
October 6, 2026
Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution
October 6, 2026
OpenAI Agents Edit Wikis, Make Millions of Wikimedia Requests
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us