Overview of the Blinder Tunnel campaign | Image: Unit 42
At a Glance
| Actor | CL-STA-1178, assessed as Iranian state-aligned (high confidence, per Unit 42) |
| Activity | Fake job lures, trojanized coding tests, GitHub-based espionage malware, credential phishing |
| Targets | An individual in Iraq’s critical infrastructure sector; an Israeli entity in a linked campaign |
| Scale | Highly targeted; no wider victim count disclosed |
| Law enforcement | No arrests or charges; GitHub removed the malicious accounts |
| Sources | Unit 42; Elastic Security Labs |
TL;DR
Iran-linked attackers posed as Dubai Airports recruiters to hook an Iraqi engineer. Their fake coding test ran malware the moment it was opened in Visual Studio. The malware then took orders through GitHub and opened tunnels into the victim’s network.
What Happened
A Fake Recruitment Process
The attackers prepared their infrastructure as early as November 2025. Then, in late March 2026, they contacted a likely software engineer about a development job. First, they sent a fake “Dubai Airports Careers” portal with a 10-question HR survey. That portal did nothing harmful. Instead, it built trust for the next step.
In April, the target received a “coding assessment.” The archive held a C# flight management project with a planted bug to fix. A readme file addressed the target by full name. Unit 42 stresses that it knows of no breach of Dubai Airports itself.
Malware on Project Load
The trap sat in the project file. Visual Studio quietly runs a background build when it opens a project. The attackers hijacked one step of that build. As a result, the malware ran “the moment the project was loaded into the IDE, even before the developer attempted to compile the code.”
Next, a renamed Microsoft binary loaded a tampered config file. This trick, called AppDomainManager hijacking, handed control to the malware and turned off Event Tracing for Windows. Finally, DLL sideloading loaded the main loader, ShelbyLoader V2.
GitHub as Command Center
ShelbyLoader V2 checks in with a GitHub repository every 63 seconds. It uploads a machine fingerprint, then pulls down commands. If that channel fails, it searches GitHub issues for hidden, encrypted notes that point to a new repository.
The loader then decrypts the main backdoor, ShelbyC2 V2. A separate module runs PowerShell commands without launching PowerShell.exe. Later, the attackers added Blackwood, a tool that runs the Chisel tunneling utility in memory. It creates a reverse proxy into the victim’s internal network.
Who Is Behind It
Unit 42 tracks the group as CL-STA-1178. It assesses “with high confidence” that the activity “aligns with an Iranian-nexus threat.” The evidence includes servers on an Iranian ISP and Persian-language domains. An MP3 file of the “Peaky Blinders” theme song also carried metadata from an Iranian music site. However, links to specific known Iranian groups remain low confidence.
The group’s “Peaky Blinders” branding ties it to earlier work. In March 2025, Elastic Security Labs described “The Shelby Strategy,” which hit an Iraqi telecom firm. That campaign also used GitHub for command-and-control. Elastic noted a major flaw then: anyone holding the embedded token could “fetch commands sent by the attacker.” No government has charged anyone over either campaign.
Impact and Scale
The Blinder Tunnel campaign was narrow by design. Unit 42 describes one confirmed target in Iraq’s critical infrastructure sector. Yet the group’s wider footprint includes telecom, aviation, and other targets across Iraq, Israel, and the UAE.
Notably, the attackers’ own mistakes exposed more. They reused a tunneling server for phishing. That led Unit 42 to a May-June 2026 campaign against an Israeli entity. It used war-themed fake Google Drive pages to steal logins. GitHub has since taken down the malicious accounts Unit 42 found.
How to Stay Protected
Unit 42 says organizations must secure developer environments and watch cloud traffic. Practical steps include:
- Treat unsolicited coding tests as untrusted, and open them only in isolated virtual machines.
- Review .csproj files for custom build targets before loading any outside project.
- Flag Microsoft binaries running from user app data folders under new names.
- Alert on .config files that load custom AppDomainManagers or disable ETW.
- Monitor unusual GitHub API traffic from non-developer processes.
- Verify recruiter contacts through the company’s official website.
For engineers, the lesson is simple. A real employer will not need you to run its code on your work machine.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!