Unit 42: Iranian-aligned CL-STA-1178 posed as Dubai Airports IT with a trojanised Visual Studio coding test ("Blinder Tunnel") to hit Iraqi critical infrastructure; ShelbyLoader V2 used GitHub for command and control
Palo Alto Networks Unit 42 reported on 6 October 2026 that a threat cluster it tracks as CL-STA-1178, which it assesses with high confidence aligns with an Iranian-nexus actor, has been impersonating the Dubai Airports IT department to send trojanised coding challenges to high-value targets. In the campaign Unit 42 calls Blinder Tunnel, infrastructure staged as early as November 2025 was activated in March 2026 against an individual in Iraq's critical infrastructure sector: a fake offline "Dubai Airport Careers" Inno Setup app led to a personalised Visual Studio project presented as an at-home assessment. Opening it abused a native .csproj build file, then AppDomainManager hijacking and DLL sideloading through a legitimate Microsoft-signed vshost32.exe, to install ShelbyLoader V2, which beaconed to the GitHub API with a hard-coded personal access token and used GitHub issues as a fallback channel, plus a PowerShell engine and an in-memory Chisel tunnelling loader called Blackwood. Unit 42 links the actor to earlier activity Elastic Security Labs tracked as The Shelby Strategy (with a "Peaky Blinders" theme throughout) and to a May–June 2026 credential-harvesting campaign against an Israeli entity; targets include telecommunications, aviation and other critical entities in Iraq, Israel and the UAE. Unit 42 found no evidence of any compromise of Dubai Airports, and GitHub has taken down the infrastructure it identified. Primary: Unit 42.
- Product
- Windows developer workstations (Visual Studio .csproj projects); GitHub API abused for C2
- Versions
- n/a — targeted espionage campaign; no product CVE
- Exploited in Australia?
- unknown
- Patch to
- Treat recruitment coding tests and project files from outside parties as untrusted code: open them only in a disposable VM, and note that building or even loading a .csproj can run attacker-supplied tasks. Hunt for vshost32.exe running outside Visual Studio paths with a .config file next to it (AppDomainManager hijacking), unexpected Chisel tunnels, and workstation processes calling api.github.com with personal access tokens. Unit 42's report lists indicators.
Primary: Unit 42 — Blinder Tunnel campaign targets Iraqi critical infrastructure (6 Oct 2026) · Cyber Security News — Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure (6 Oct 2026)
