Palo Alto Exposes Blinder Tunnel Iranian Cyber Espionage Campaign
Palo Alto Networks Unit 42 uncovered a sophisticated Iranian-linked espionage campaign called Blinder Tunnel, targeting critical infrastructure in Iraq, the UAE, and Israel using fake job interviews and Visual Studio exploits.

Unit 42 researchers at Palo Alto Networks have uncovered a sophisticated espionage and attack campaign, designated CL-STA-1178 and dubbed Blinder Tunnel, with strong links to Iranian state-sponsored actors. The operation involved impersonating IT managers at Dubai Airports, a fake software developer interview test, and a malicious payload triggered via Visual Studio.
According to the report, campaign infrastructure was prepared as early as November 2025, and by March 2026, the attackers focused their infiltration attempts on critical infrastructure in Iraq. Palo Alto emphasized that there is no evidence of a breach, compromise, or vulnerability in Dubai Airports systems. The company name was used by the attackers strictly for impersonation and social engineering purposes.
The initial phase resembled a standard recruitment process. The target, likely a software engineer in Iraq, received outreach from individuals posing as Dubai Airports IT managers offering a development role. The victim was asked to download a file named Dubai Airport Careers, which deployed a local and fake career portal featuring a login screen and a ten-question HR survey. No malware was deployed at this stage, and no data was stolen, as the goal was to build credibility before springing the trap.
By April 2026, the technical assessment phase arrived. The attackers sent a Visual Studio archive named DubaiAirport_Carrers_IT_Test.zip, containing a C# project for a flight management system and a Readme.md file with personalized instructions for the developer. The task appeared benign: find and fix a bug in the code, specifically a for loop skipping the final element. However, the attack initiated the moment the project was loaded into Visual Studio, even before the developer attempted to run or compile the code.
The project file defined a command named GetFrameworkPaths, which automatically executed via the Design-Time mechanism of Visual Studio. This triggered a chain using AppDomainManager and DLL Sideloading to execute ShelbyLoader V2. The attackers also utilized a legitimate Microsoft file, renamed to RuntimeBroker.exe, alongside its configuration file to launch the malicious component.
Control was then handed over to infrastructure designed to mimic routine corporate activity. The malware used the GitHub API to retrieve AES-256 decryption keys and download additional payloads. Even if the primary repository was blocked, the attackers had a backup solution: searching for encrypted comments inside GitHub Issues to extract alternative C2 addresses. Following these findings, GitHub removed the infrastructure utilized by the campaign.
Subsequently, PsProxy.dll was deployed, allowing attackers to execute PowerShell commands directly in memory without creating a powershell.exe process. Concurrently, Blackwood was activated, executing the Chisel tunneling tool in memory and opening a SOCKS5 proxy to route traffic into the victim's internal network.
Researchers also discovered clear signs that the attackers adopted branding from the Peaky Blinders television series. GitHub accounts and repositories were named after characters from the show, such as ArthurShelby and peakyblinders-tm, and one repository even hosted the audio file of the theme song, Red Right Hand, under the name Peaky Blinders Team.mp3.
This specific file helped researchers trace the origin. Its metadata contained a field pointing to MusicDel.ir, an Iranian music download platform, indicating the file was downloaded from an Iranian site before being uploaded to the campaign infrastructure. Blackwood infrastructure also pointed to Iran, with researchers identifying an IP address belonging to the Iranian ISP TOSE'EH ERTEBATAT NOVIN ARIA, alongside a tunneling server in Germany linked to Persian-language domains.
The same infrastructure was tied to a phishing campaign targeting an Israeli entity in May and June 2026. The attackers set up a page disguised as Google Drive offering a download named WarUnPublishedDocuments.zip. Clicking the download led to a fake Google login page designed to steal credentials. Google confirmed its systems were not breached and blocked the domains used for impersonation.
Palo Alto noted this activity may be a continuation of previous campaigns documented by Elastic Security Labs under The Shelby Strategy. Researchers highlighted overlaps in tactics with Iranian groups such as Screening Serpens, known for dream job lures in the aviation sector and AppDomainManager usage, and Agent Serpens, known for utilizing GitHub as a dead-drop resolver mechanism.
The uncovered campaigns targeted telecom, aviation, and infrastructure sectors in Iraq, the United Arab Emirates, and Israel. At the time of publication, Palo Alto could not determine whether the infection in Iraq succeeded or if credentials were stolen from the Israeli target.





