Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Between March and April 2026, an Iranian-nexus threat actor hooked a critical infrastructure professional in Iraq with a fake job offer from Dubai Airports. The vector was not a suspicious PDF attachment, but a complete, ready-to-compile Visual Studio project that executed its payload before the developer even pressed 'build.' The Unit 42 report, published today, reconstructs the Blinder Tunnel campaign in the most granular technical detail available to date.
- Threat actor CL-STA-1178 impersonated Dubai Airports to recruit Iraqi software engineers with trojanized coding challenges, active from March 2026 with staging observed since the previous November.
- The .csproj file was weaponized to execute payloads during Visual Studio's design-time build, before any explicit compilation by the developer.
- Command-and-control infrastructure abused the GitHub API, using repositories and issues as a resilient mechanism, while tunneling passed through in-memory-loaded Chisel.
- Unit 42 attributes the activity to an Iranian threat actor with high confidence; OpSec errors linked Blinder Tunnel to a separate credential-harvesting campaign against an Israeli entity.
How the Trap Works: From Decoy to Invisible Execution
The chain begins with an Inno Setup installer that deploys an offline career portal containing a 10-question questionnaire. No suspicious network activity: the decoy is harmless, designed to lower the victim's psychological defenses. Immediately after comes the ZIP archive with the Visual Studio project, apparently a routine C# programming challenge.
The project contains an intentional bug in a for loop. The developer, invited to fix it, loads the file into the IDE. That is when the mechanism triggers: the .csproj file, the heart of Visual Studio's build system, has been weaponized to abuse the design-time evaluation process. The payload activates the moment the project is loaded, even before the developer attempts to compile the code.
From there, the chain proceeds with three concatenated techniques: AppDomainManager hijacking to manipulate the .NET execution context, DLL sideloading to ensure persistence, and the in-memory loading of ShelbyLoader V2, the component that establishes the link to the attackers' infrastructure.
"The attackers weaponized the C# project's .csproj configuration file by misusing Visual Studio's built-in evaluation process. This method caused the payload to execute the moment the project was loaded into the IDE, even before the developer attempted to compile the code" — Unit 42 researchers
Abusing GitHub: Legitimate Cloud as C2 Infrastructure
ShelbyLoader V2 does not communicate with traditional malicious domains. It uses the GitHub API, leveraging public repositories and issues as a fallback command-and-control mechanism. The choice is tactically significant: traffic to api.github.com is normal in virtually every development environment, making detection based on known network indicators impractical.
The same GitHub repository hosted an in-memory wrapper for the open-source Chisel utility, a legitimate tunneling tool that attackers repurposed as a bridge between their external infrastructure and compromised networks. The combination of a trusted cloud platform, official APIs, and open-source tools represents a living-off-the-cloud pattern that challenges defensive architectures based on domain blocklists.
GitHub removed the identified malicious infrastructure upon notification. The source does not specify intervention timelines or whether additional related repositories were identified.
The Peaky Blinders Signature and the Errors That Betray
One of the most unusual pieces of convergent evidence concerns the soundtrack of the TV series Peaky Blinders. Attackers embedded the soundtrack in malware files as metadata, creating an infrastructural link between Blinder Tunnel and a separate credential-harvesting campaign directed at an Israeli entity. OpSec errors — the failure to replace shared artifacts across distinct operations — allowed Unit 42 to trace this overlap.
The Peaky Blinders theme is not decorative. It functions as a campaign watermark, an element intended to facilitate internal operations management that instead provided researchers with proof of correlation between different attacks.
The source does not clarify the precise relationship between CL-STA-1178 and Screening Serpens, another Iranian group active in the same period that employed the same AppDomainManager hijacking technique to disable .NET security mechanisms. Technical overlaps exist; the source does not prove actor identity.
Why It Matters
The brief does not document specific remedial measures released by Unit 42 or the vendor. The source does not specify the nature of any data potentially exposed, nor the extent of compromise beyond the initial foothold on the documented victim's system. The exact number of Iraqi victims remains unknown: only one individual in the critical infrastructure sector is confirmed with certainty.
The campaign exploits no zero-day vulnerabilities or documented public exploits: no CVE is mentioned in the report. The entire chain relies on refined social engineering, developers' implicit trust in their development toolchain, and the use of legitimate platforms as attack vehicles. This model makes technical detection insufficient without parallel reinforcement of recruitment communication verification and scanning of third-party projects before loading them into an IDE.
The source does not indicate whether Dubai Airports was informed of the impersonation campaign or adopted specific countermeasures. Unit 42 explicitly rules out any breach of the entity's infrastructure.
What Changes for Software Developers in Sensitive Contexts
Blinder Tunnel marks an inflection point in recruitment phishing. The vector is no longer an Office document with macros or a PDF with a malicious link, but a complete, technically credible development project that exploits legitimate mechanisms of the .NET toolchain. The target is not the generic user but the professional with privileged access to codebases and production environments.
Visual Studio's design-time build, normally invisible to the developer, becomes an attack surface. The compilation itself, a routine and necessary act, is instrumentalized as an execution trigger. Cloud development, with its ecosystem of APIs and integrated services, offers C2 channels that traditional egress filtering policies do not cover.
The Unit 42 report is the first to reconstruct Blinder Tunnel as a unitary campaign, linking attacks previously treated as isolated episodes. The high-confidence assessment on Iranian attribution rests on this holistic reconstruction, not on single technical indicators.
"This is the first report that not only ties together these disparate attacks as related activity, but tracks the evolving 2026 activity and the Blinder Tunnel campaign as a whole" — Unit 42 researchers
Questions and Answers
Was Dubai Airports compromised?
No. Unit 42 explicitly rules out any breach of Dubai Airports' infrastructure. Attackers impersonated the entity's IT department as a social engineering element.
How many victims are confirmed?
Only one, in the Iraqi critical infrastructure sector, with certain documentation. The source does not specify whether other unreported victims exist.
Is there a proven relationship between CL-STA-1178 and Screening Serpens?
No. The two entities share the AppDomainManager hijacking technique in the same period, but the source does not prove an actor link. They may be correlated clusters, distinct actors with access to shared tools, or separate groups that independently developed the same capability.
Sources
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.