Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Iran-Linked Blinder Tunnel Campaign Targets Iraqi Infrastructure Through Fake Coding Test
Iran-Linked Blinder Tunnel Campaign Targets Iraqi Infrastructure Through Fake Coding Test
Read Time:3 Minute, 30 Second

An Iranian-aligned threat cluster used a convincing recruitment exercise to target a likely Iraqi software engineer connected to critical infrastructure. The campaign, tracked as Blinder Tunnel, paired a fake Dubai Airports careers portal with a weaponized Visual Studio project that could execute attacker code as soon as the victim opened the supposed coding test.

Palo Alto Networks Unit 42 tracks the activity as CL-STA-1178 and assessed with high confidence that it has an Iranian nexus. Researchers found no evidence that Dubai Airports itself was breached or vulnerable; its identity was used as social engineering cover. Preparations date to November 2025, while the observed operation became active in March 2026.

A patient recruitment lure built trust first

The initial package was an Inno Setup application named “Dubai Airport Careers.” It opened a local imitation of a recruitment site, accepted credentials supplied by the supposed hiring team and displayed a ten-question human-resources form. Investigators found that this first stage neither stole the entered information nor installed malware.

That restraint appears deliberate. By making the portal behave like a plausible application process, the operators reduced suspicion before delivering a personalized archive named DubaiAirport_Carrers_IT_Test.zip. Its instructions addressed the target and asked the candidate to open a C# flight-management project, then correct a simple loop error.

The technique exploits an important developer trust assumption: a source project looks like material to inspect, not an executable installer. Yet modern development environments evaluate project metadata automatically. The victim did not need to compile the program for the malicious chain to begin.

Visual Studio project launches the infection

A modified FlightManager.csproj abused Visual Studio’s background evaluation behavior. It created a misleading RuntimeBrokers directory beneath local application data and launched RuntimeBroker.exe. The attackers then altered an application configuration file to hijack AppDomainManager, causing malicious code to load before the legitimate host application.

The configuration also disabled Event Tracing for Windows, weakening a telemetry source defenders use to identify suspicious .NET execution. The chain proceeded through DLL sideloading: a renamed legitimate Visual Studio hosting binary loaded an attacker-controlled RuntimeBroker.dll, identified as the ShelbyLoader V2 loader.

ShelbyLoader established persistence with a registry Run value, collected a fingerprint of the host and communicated through GitHub’s API. It could upload system details, retrieve tasks and use encrypted information in GitHub issue comments as a fallback. GitHub removed infrastructure identified during the investigation.

Backdoor and tunnels support deeper access

The loader decrypted ShelbyC2 V2, a backdoor capable of receiving operator commands. A component named PsProxy.dll executed commands through the PowerShell engine without launching the familiar PowerShell.exe process, helping activity blend past detections based only on process names.

The attackers also staged Blackwood, an in-memory wrapper around the Chisel tunneling utility. It could create encrypted tunnels and a reverse SOCKS proxy, providing a route to systems beyond the initially compromised workstation. In a critical-infrastructure environment, that capability turns one developer endpoint into a potential pivot point for long-term access.

Researchers associated the cluster with Iran through infrastructure, victim selection and an operational mistake: metadata in an audio file referenced an Iranian music site. Related credential-harvesting infrastructure also targeted an Israeli entity during May and June 2026.

Detection and prevention priorities

Organizations should treat unsolicited coding exercises as executable content. Candidates can verify recruiters through independent corporate channels and open unfamiliar projects only in disposable, isolated environments. Security teams should monitor development tools as closely as office documents and browsers.

  • Alert on unusual msbuild.exe activity and projects that launch processes during evaluation.
  • Investigate signed binaries loading unknown DLLs from user-writable directories.
  • Monitor changes to .NET configuration files and attempts to disable ETW.
  • Review GitHub API traffic that does not match normal repository workflows.
  • Isolate suspected hosts, rotate exposed credentials and examine lateral-movement paths.

The campaign succeeds by making each step look familiar: a job application, a coding task, Visual Studio components and GitHub traffic. Defenders need to evaluate the complete sequence rather than trusting any one legitimate-looking element. For engineering teams operating around sensitive infrastructure, project files from outside the organization warrant the same caution as macros, scripts and unsigned executables.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Iran-Linked Blinder Tunnel Campaign Targets Iraqi Infrastructure Through Fake Coding Test, use the discussion on Forum.

>> forum community

Comments

Leave a Reply