Blinder Tunnel: Iran-Linked Malware Abuses GitHub C2
Unit 42 ties Iran-nexus CL-STA-1178 to Blinder Tunnel, which hit Iraqi critical infrastructure in March 2026 using fake Dubai Airports lures and GitHub-hosted C2.

Executive Summary
An Iranian state-aligned threat actor used GitHub's API as command-and-control infrastructure to compromise an Iraqi critical-infrastructure target in March 2026, according to research published today by Palo Alto Networks Unit 42. The cluster, tracked as CL-STA-1178, staged its attack infrastructure as early as November 2025 and activated the campaign — which Unit 42 calls Blinder Tunnel — after a months-long social-engineering operation impersonating the Dubai Airports IT department.
The campaign matters to defenders well beyond the Middle East because of its initial-access chain: weaponized .csproj developer files, AppDomainManager hijacking, and DLL sideloading combine to execute a custom loader, ShelbyLoader V2, inside trusted Windows processes. Unit 42 attributes the activity to an Iranian nexus with high confidence and links it to prior operations tracked by Elastic Security Labs as "The Shelby Strategy."
Technical Analysis
Unit 42 describes a three-step execution chain. The attackers first delivered a trojanized Microsoft developer project file (.csproj) — a format developers routinely open without suspicion — which then triggered AppDomainManager hijacking, an evasion technique Unit 42 says Iranian groups including Screening Serpens are adopting with increasing frequency. That stage in turn enabled DLL sideloading to launch ShelbyLoader V2.
For C2, the operators leaned on GitHub's legitimate API surface — a "living off the cloud" pattern — to blend malicious traffic with ordinary enterprise cloud activity. According to Unit 42, the GitHub repositories served three functions: fetching decryption keys, downloading payloads, and using GitHub issues as a resilient fallback C2 channel. Before takedown, one repository also hosted an in-memory wrapper that executed the open-source Chisel tunneling utility, which the attackers used as a bridge between external infrastructure and the compromised network. GitHub has since removed the malicious infrastructure Unit 42 identified.
Unit 42 says the campaign carries a "Peaky Blinders" branding theme — infrastructure components named after the show, and even the series theme song embedded in the malware with metadata that helped investigators correlate infrastructure. The researchers credit operational-security and cryptographic missteps by the attackers, including tools exposed on public repositories and overlapping phishing and tunneling infrastructure, for linking Blinder Tunnel to a separate May–June 2026 credential-harvesting campaign against an Israeli entity that used conflict-themed Google Drive lures.
Targeting has spanned telecommunications, aviation, and other critical entities across Iraq, Israel, and the UAE, per Unit 42. The March 2026 intrusion focused on a single individual in Iraq's critical-infrastructure sector, recruited through a fake Dubai Airports careers process.
Tactics, Techniques & Procedures
The chain sequences social engineering into execution hijacking and then into cloud-abused C2. Spearphishing via a fake recruitment portal (T1566.003) delivers the .csproj file; AppDomainManager hijacking (T1574.014) and DLL sideloading (T1574.002) establish execution of ShelbyLoader V2; GitHub repositories act as a dead-drop resolver (T1102.001) and bidirectional C2 fallback (T1102.002); Chisel provides protocol tunneling (T1572) shaped as web traffic (T1071.001). The sequencing is notable because each stage relies on a trusted artifact — a developer file, a signed host process, a public code-hosting service — rather than a novel exploit.
Threat Actor Context
Unit 42 tracks the activity as CL-STA-1178 and assesses with high confidence that it aligns with an Iranian nexus. The cluster overlaps with activity Elastic Security Labs previously documented as "The Shelby Strategy," and Unit 42 describes its report as the first to tie the disparate attacks together and track the evolving 2026 activity as a single campaign. The actor's repeated use of television-show branding for malware and infrastructure is a consistent identifying trait across operations.
Mitigations & Recommendations
Given the absence of published file hashes or domains in the source material, defenders should focus on behavioral detection. Monitor developer endpoints for .csproj files that spawn unexpected child processes or load assemblies outside normal build tooling, and alert on AppDomainManager configuration values pointing to non-standard paths. Treat outbound GitHub API traffic from build servers and developer workstations that does not correlate with legitimate CI/CD activity as suspicious, particularly requests to repositories that fetch encrypted blobs or poll issues on a schedule. Because the actor used Chisel for tunneling, inspect for the utility's characteristic traffic patterns and for in-memory execution of tunneling binaries. Organizations in telecommunications, aviation, and critical infrastructure across the Middle East should review recruitment-themed email and messaging lures referencing Dubai Airports or similar aviation employers.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.

