Iranian state-backed threat actors have been observed leveraging a fraudulent Dubai Airports recruitment campaign to compromise Iraqi critical infrastructure organizations through a weaponized software development assessment.
The operation, dubbed Blinder Tunnel, transformed what appeared to be a legitimate coding exercise into a sophisticated intrusion mechanism capable of establishing remote access, maintaining persistence, and creating covert network tunnels within targeted environments.
Researchers determined that preparations for the campaign began as early as November 2025, with active attacks launching in March 2026 against what is believed to have been an Iraqi software engineer. The activity cluster, tracked as CL-STA-1178, has been attributed with high confidence to an Iran-linked threat actor.
Targets were initially directed to a convincing offline recruitment portal posing as a Dubai Airports careers platform. After completing the first stage of the supposed hiring process, victims received a customized Visual Studio project presented as a take-home technical assessment. Investigators emphasized that while the attackers impersonated Dubai Airports IT personnel, there is no indication that the airport operator’s systems were compromised or involved in the campaign.
.webp)
The incident highlights a growing trend in which threat actors abuse software development tools and workflows. By disguising malicious code within what appears to be a legitimate developer project, attackers can trigger execution through trusted build environments before a victim writes, compiles, or reviews any code.
According to researchers, the campaign relied extensively on legitimate cloud services to blend malicious communications with normal network traffic and evade detection.
Fake Recruitment Process Opens the Door
In late March, victims were presented with an installer named Dubai Airport Careers, which served as the first stage of the fake recruitment workflow.
The application deployed a locally hosted imitation careers portal that required credentials supplied by the alleged recruiters and guided applicants through a ten-question human resources questionnaire. Notably, the portal itself neither harvested sensitive information nor deployed malware, a tactic likely designed to strengthen the illusion of legitimacy and lower suspicion.
Candidates who completed this stage later received a compressed archive titled DubaiAirport_Carrers_IT_Test.zip. Inside was a personalized Readme.md instructing the recipient to review a C#-based Flight Management System project and correct a basic programming error.
.webp)
This technique mirrors previous Iranian cyber espionage operations that have used fabricated employment opportunities and technical assessments to lure professionals into executing malicious content.
Weaponized Visual Studio Project
The attack chain began as soon as the Visual Studio project was opened.
A malicious FlightManager.csproj file exploited Visual Studio's background project evaluation process to silently create a deceptive RuntimeBrokers directory within local application data and execute a rogue RuntimeBroker.exe process, all without requiring the victim to build or run the project.
Attackers then manipulated the RuntimeBroker.exe.config file using an AppDomainManager hijacking technique, ensuring their code executed before the legitimate application initialized. The modified configuration also disabled Event Tracing for Windows (ETW), reducing visibility into suspicious .NET activity and complicating detection efforts.
Researchers noted that similar AppDomainManager abuse has appeared in multiple recent intrusion campaigns associated with Iranian threat actors.
The final stage of the initial compromise relied on DLL sideloading, where a renamed legitimate Visual Studio component loaded a malicious RuntimeBroker.dll known as ShelbyLoader V2.
Security teams are advised to monitor for trusted, signed applications loading unexpected DLLs from non-standard locations, unusual msbuild.exe executions, suspicious developer project activity, and unauthorized modifications to .NET configuration files.
GitHub-Based Command and Control
After installation, ShelbyLoader V2 established persistence through a Windows Registry Run key, collected system information, and communicated with attacker-controlled infrastructure using the GitHub API.
The malware transmitted a unique host fingerprint, retrieved commands from operator-controlled repositories, and included fallback mechanisms that concealed encrypted instructions within GitHub issue comments should primary communication channels become unavailable. The GitHub infrastructure identified during the investigation has since been removed.
ShelbyLoader then decrypted and launched the ShelbyC2 V2 backdoor, which leveraged PsProxy.dll to execute PowerShell commands through the PowerShell engine without spawning PowerShell.exe, helping attackers evade endpoint monitoring solutions.
The malware framework also deployed Blackwood, an in-memory wrapper around Chisel, enabling encrypted tunneling and reverse SOCKS proxy functionality. This capability allowed operators to move laterally across compromised networks and access internal systems while minimizing detection.
Indicators Point to Iranian Operations
Researchers linked the activity to Iranian threat operators based on infrastructure overlaps, victimology, operational patterns, and a notable operational security mistake. Metadata embedded in an audio file used during the campaign referenced MusicDel[.]ir, providing an additional clue regarding the operators' origins.
Investigators also uncovered related credential-harvesting infrastructure targeting an Israeli organization during May and June 2026, suggesting the campaign may be part of a broader regional espionage effort.
Defensive Recommendations
Organizations should independently verify recruiting communications and technical assessments through trusted channels before opening or executing supplied files. Security teams are encouraged to isolate suspicious systems, rotate potentially exposed credentials, and review unusual GitHub API traffic that falls outside normal development operations.
Additional protections include implementing phishing-resistant multi-factor authentication, restricting execution of untrusted Visual Studio projects, monitoring for .NET configuration tampering, and carefully validating URLs before entering login credentials.
The campaign demonstrates how modern threat actors are increasingly exploiting trusted developer workflows, turning routine recruitment exercises into highly effective entry points for long-term cyber espionage operations.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
