Iranian hackers pose as Dubai Airports to hit Iraqi targets

Published

The job offer looked real: a development role in the Dubai Airports IT department, a polished careers portal, a ten-question HR questionnaire and, finally, a take-home coding test addressed to the candidate by full name. The test was the attack. According to new research from Palo Alto Networks' Unit 42, opening the project in Visual Studio was enough to infect the machine, before the engineer had compiled a single line.

Unit 42 tracks the operators as CL-STA-1178 and assesses with high confidence that they are an Iranian state-aligned actor. It calls the campaign "Blinder Tunnel" and says it targeted Iraqi critical infrastructure in March 2026, after attack infrastructure was staged as early as November 2025 and left dormant for months.

A recruitment process built to lower a guard

The lure arrived in stages. First came an installer for an offline "Dubai Airport Careers" site that asked the target to log in with credentials the fake recruiters supplied. Unit 42 found that this portal did nothing malicious at all: submitting the questionnaire sent no data anywhere. Its job was to build trust. A month later the same target received a Visual Studio project archive presented as a flight-management coding exercise with a deliberate bug to fix.

Unit 42 stresses it is not aware of any breach or vulnerability in Dubai Airports' own systems; the brand was simply borrowed. The approach echoes the fake coding challenges another Iranian group used against developers earlier this year.

Opening the project was the trigger

The researchers describe a three-step chain. A tampered project file abused the background build Visual Studio runs when a solution is loaded, copying hidden binaries into a folder under the user's local app data and launching them. A renamed, legitimate Microsoft hosting process was then forced, through a technique called AppDomainManager hijacking, to load the attackers' code first, with a configuration line that switched off Event Tracing for Windows, a key source of telemetry for security tools. Finally, DLL sideloading loaded the main implant, which Unit 42 named ShelbyLoader V2.

That loader fingerprinted the host, checked for analysis sandboxes, set registry persistence and then talked to its operators through the GitHub API, using repositories to fetch keys, payloads and commands. If its access token was revoked, it fell back to reading encrypted instructions hidden in comments on GitHub issues. Further modules ran PowerShell without launching powershell.exe and tunnelled traffic with the open-source Chisel utility. GitHub has taken down the infrastructure Unit 42 identified.

Peaky Blinders, and the mistakes that gave it away

The group names its tooling and infrastructure after the British crime drama Peaky Blinders, and even embedded the show's theme song in its malware. Unit 42 says that habit, along with tools left in public repositories and reuse of phishing and tunnelling infrastructure, let it tie Blinder Tunnel to a separate credential-harvesting campaign against an Israeli entity in May and June 2026, and to earlier activity Elastic Security Labs documented as The Shelby Strategy. The cluster's targets span telecommunications, aviation and other critical sectors in Iraq, Israel and the United Arab Emirates.

Treat take-home tests as untrusted code

For organizations in Iraq and the wider Gulf, the practical lessons are concrete. Engineers should open unsolicited projects only in an isolated environment, since loading a solution can execute code. Defenders can hunt for renamed Microsoft binaries running from user profile folders, processes loading unsigned DLLs outside system directories, application configuration files that disable ETW, and unexpected workstation traffic to the GitHub API. Unit 42's report carries the full technical detail and indicators.

The careful part of this operation was the patience. The infrastructure sat ready for four months, waiting for one person to open one file.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions