Iranian-nexus crew wore a Dubai Airports badge to reach an Iraqi engineer
Unit 42 published research Tuesday on a cluster it calls CL-STA-1178, which impersonated Dubai Airports recruiters to plant malware on an Iraqi critical-infrastructure target. The intrusion ran in March; the news is the disclosure, not a live breach.
Palo Alto Networks' Unit 42 published on Tuesday 6 October an account of a campaign it names “Blinder Tunnel,” after the “Peaky Blinders” branding the operators used across their infrastructure — GitHub accounts named for the British crime drama and its characters, one repository carrying the show’s theme song. The target, Unit 42 assesses, was a single Iraq-based software engineer. The approach began with a fake Dubai Airports careers application, built in Inno Setup, that hosted a local imitation of the careers site, demanded credentials supplied by the supposed recruiters and presented a ten-question HR form. That stage stole nothing and ran nothing: Unit 42 reads the restraint as deliberate, a trust-building step before the payload. The follow-up archive, DubaiAirport_Carrers_IT_Test.zip, asked the candidate to open a C# flight-management project and fix a loop error — a fifteen-to-twenty-minute coding assessment.
Opening the project was sufficient. A weaponised FlightManager.csproj abused Visual Studio’s background evaluation to create a RuntimeBrokers folder under local application data and launch RuntimeBroker.exe before the developer ever hit build. From there the chain ran through AppDomainManager hijacking with ETW disabled, DLL sideloading, and ShelbyLoader V2, to a ShelbyC2 V2 backdoor using the GitHub API for command and control with GitHub Issues as fallback, plus a Chisel wrapper called “Blackwood” for reverse SOCKS tunnelling. GitHub has taken the infrastructure down. The same cluster ran credential harvesting against an Israeli entity in May and June using war-themed lures. Unit 42 says it is not aware of any breach or compromise of Dubai Airports systems; the brand was impersonated, nothing more.
Assessment: Two things to hold onto. First, the dating: infrastructure staged as early as November 2025, activated late March 2026, published October 2026. Any coverage that reads this as a current Iraqi breach is wrong, and several aggregators are already headlining the Dubai Airports name in a way that invites exactly that error. Second, the attribution floor. Unit 42 is high-confidence Iranian-nexus but found only low-confidence overlaps with Screening Serpens (UNC1549) and Agent Serpens (APT35/Charming Kitten) — not enough to name either. Expect the shorthand “Charming Kitten hit Iraq” within a week. The Gulf angle is that a UAE commercial brand was used as operational cover by a third party; Dubai Airports and the UAE authorities have said nothing in this window.