Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Login screen headed Dubai Airports Careers Login, with User Name and Password fields, a yellow LOGIN button and a laptop illustration on the left.
Screenshot: Unit 42 (Palo Alto Networks), the fake Dubai Airports careers portal the attackers had the target install before sending a trojanized coding test, Oct 6, 2026 (fair use).

Threat Intel

Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test

Unit 42 researchers said on October 6 that an Iranian state-aligned group it tracks as CL-STA-1178 sent an Iraq-based engineer a fake coding assessment that ran malware as soon as Visual Studio opened the project, then took its orders through GitHub repositories and issue comments.

Priya Shah, Threat IntelSingapore5 min read

SINGAPORE - An Iranian state-aligned hacking group posed as the IT department of Dubai Airports and handed a software engineer in Iraq a job test that infected the computer the moment the project was opened, researchers at Palo Alto Networks' Unit 42 said on Tuesday. Unit 42 tracks the activity as CL-STA-1178 and calls the operation "Blinder Tunnel," a campaign that targeted Iraqi critical infrastructure in March 2026 after infrastructure was staged as early as November 2025. "We assess with high confidence that this activity aligns with an Iranian-nexus threat," the researchers wrote, adding that theirs is the first report to tie together attacks other vendors had described one at a time. For security operations teams, the report matters less for the attribution than for where the attack lived: inside a developer's own tools, with its command traffic riding GitHub's API.

Unit 42 diagram titled Dual Attack Vectors and Command and Control: trojanized coding challenge, three-step chain (.csproj, AppDomainManager hijack, DLL sideloading), ShelbyLoader V2 with GitHub beaconing and issues-search fallback, ShelbyC2 V2, PsProxy, and the Blackwood Chisel tunnel in a peakyblinders-tm repository.
Graphic: Unit 42 (Palo Alto Networks), overview of the Blinder Tunnel campaign, from the trojanized coding challenge through ShelbyLoader V2, ShelbyC2 V2, PsProxy and the Blackwood Chisel tunnel, plus the parallel credential-phishing campaign, Oct 6, 2026 (fair use).The campaign pairs a trojanized coding test with a parallel phishing lane.

The approach was patient. Starting in late March, the attackers told the target to install a file named Dubai Airport Careers, an Inno Setup installer that unpacked an offline site posing as a careers portal, with login credentials supplied by the "recruiters." Behind the login sat a 10-question HR questionnaire that sent nothing anywhere, which Unit 42 described as a harmless decoy meant to build credibility before the real payload arrived. Unit 42 found the campaign through VirusTotal, after multiple file submissions from a submitter based in Iraq, and said it is not aware of any breach, compromise or vulnerability within Dubai Airports infrastructure or systems.

The payload came in April as a coding assessment. The archive, DubaiAirport_Carrers_IT_Test.zip, with "Careers" misspelled, held a C# flight management project, a Readme.md from a purported senior manager in the Dubai Airports IT department, and an intentional bug, a for loop that skips the last element, for the candidate to fix. The trap was in the project file. The attackers defined a custom build target named GetFrameworkPaths in the .csproj, overriding a step that Visual Studio runs in its background design-time build whenever a project is opened, so the payload executed before the developer compiled anything. The target created a folder at %LOCALAPPDATA%\Microsoft\RuntimeBrokers, copied hidden binaries from the project's Resources folder into it and launched RuntimeBroker.exe. "The malware deployed, copied itself and launched in the background while the developer was still reading the deceptive Readme.md file," the researchers wrote.

Visual Studio project XML with a GetFrameworkPaths target, annotated MakeDir for LocalAppData Microsoft RuntimeBrokers, Copy of files from Resources, and Exec starting RuntimeBroker.exe.
Screenshot: Unit 42 (Palo Alto Networks), the weaponized .csproj file, whose GetFrameworkPaths target creates a RuntimeBrokers folder, copies the hidden binaries and launches the payload when Visual Studio opens the project, Oct 6, 2026 (fair use).Opening the project creates RuntimeBrokers and launches the payload.

What ran was not what its name suggested. RuntimeBroker.exe was a legitimate, signed Visual Studio hosting process, vshost.exe, renamed. A few lines in its RuntimeBroker.exe.config file performed AppDomainManager hijacking, handing control to the malware before the host application started, and one directive, etwEnable enabled="false", turned off Event Tracing for Windows, which security tools rely on to watch in-memory activity. The process then sideloaded RuntimeBroker.dll, a loader Unit 42 calls ShelbyLoader V2. It persists through a MicrosoftRuntime value under the current user's Run registry key, rechecked every 120 seconds, looks for virtualization markers and only runs if explorer.exe launched it.

Its command channel is GitHub. Every 63 seconds the loader authenticates to the GitHub API with a hard-coded personal access token, uploads a machine fingerprint to a repository called peakyblinders-tm/myLic and polls a file named Inf.txt for Base64-encoded commands. If the token is revoked, the malware falls back to the GitHub Issues Search API, queries for issues matching the current date and pulls AES-encrypted instructions hidden inside HTML comment markers in issue comments, which can point it at a new owner, repository and token. The main backdoor, ShelbyC2 V2, is decrypted in memory using a key derived from content fetched from that repository, and a module called PsProxy.dll runs PowerShell inside the hijacked process without ever starting powershell.exe. GitHub has taken down the infrastructure Unit 42 identified.

For moving deeper into a network, the group used a tool called Blackwood. On May 1 the attackers added a public repository named pubs holding Client.zip, which pairs a signed Microsoft binary, vshost32.exe, with a configuration file that sideloads Blackwood.dll. The DLL decrypts and loads the open-source Chisel tunneling utility, hidden as an 8.4 MB resource, and the recovered configuration told infected machines to open a reverse SOCKS proxy to 91.107.156[.]29. Another Blackwood server, 65.109.214[.]145, also hosted Google Drive and Google Meet lookalike domains used in May and June against an Israeli entity, offering a file named WarUnPublishedDocuments.zip that led to a fake Google login page. Unit 42 tied the operation to Iran through an Iranian internet provider behind one server, audio file metadata pointing to the Iranian music site MusicDel[.]ir, regional victimology and tradecraft with low-confidence overlaps to Screening Serpens and Agent Serpens. The group brands its tooling after the British crime drama "Peaky Blinders," a theme Elastic Security Labs documented earlier as "The Shelby Strategy."

GitHub page for public repository peakyblinders-tm/pubs with one commit and a single file, Client.zip.
Screenshot: Unit 42 (Palo Alto Networks), the attackers' public GitHub repository peakyblinders-tm/pubs holding Client.zip, the Blackwood tunneling package, before GitHub took the infrastructure down, Oct 6, 2026 (fair use).The public pubs repository held Client.zip before GitHub took it down.

Unit 42 closes its report by pointing to Palo Alto Networks products and says Cortex XDR flagged and blocked this chain, but the artifacts it published can be hunted with any endpoint and network tooling. They include MSBuild or Visual Studio design-time builds that launch executables from %LOCALAPPDATA%\Microsoft\RuntimeBrokers, renamed vshost.exe or vshost32.exe binaries beside .config files that disable ETW, the HKCU Run value MicrosoftRuntime, GitHub API and Issues Search traffic from processes that have no reason to make it, and Chisel reverse SOCKS tunnels. The researchers advised monitoring binaries that load unknown or non-standard DLLs outside system directories, and the report lists file hashes, IP addresses, phishing domains and the GitHub accounts involved. "This operation underscores the need for organizations to secure developer environments, monitor anomalous cloud platform traffic and maintain vigilance against industry-specific social engineering lures," Unit 42 wrote.

Sources:


Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.

Related stories

Threat Intel desk