DEV Community

Mark0
Mark0

Posted on

Blinder Tunnel Campaign Targets Iraqi Infrastructure

⚠️ Region Alert: UAE/Middle East

Researchers have uncovered an Iranian state-aligned threat campaign dubbed "Blinder Tunnel," tracked as CL-STA-1178, which has been active since late 2025. The campaign utilizes highly tailored social engineering lures masquerading as the Dubai Airports IT department to target high-value individuals, specifically software engineers in Iraq. The attackers employ a sophisticated three-step infection chain involving weaponized .csproj files, AppDomainManager hijacking to disable Event Tracing for Windows (ETW), and DLL sideloading to deploy custom malware such as ShelbyLoader V2 and ShelbyC2 V2.

A notable characteristic of this actor is their "living off the cloud" strategy, leveraging GitHub's API and encrypted comments within GitHub issues as a resilient command-and-control (C2) fallback mechanism. The campaign also features a distinct "Peaky Blinders" theme, with infrastructure and malware components named after characters from the television drama. Forensic analysis, including Iranian-hosted infrastructure and embedded metadata in media files, strongly aligns this activity with Iranian state-sponsored espionage operations targeting critical infrastructure in the Middle East, including the aviation and telecommunications sectors.


Read Full Article

Top comments (0)