Unit 42 says an Iranian-aligned cluster posed as Dubai Airports recruiters to reach Iraqi infrastructure
Palo Alto Networks published research on 7 October naming a campaign it calls Blinder Tunnel, run by an activity cluster it tracks as CL-STA-1178. The regional detail is the lure: a Gulf employer’s name used against an Iraqi target.
Unit 42, the threat-intelligence arm of Palo Alto Networks, published research on or around 7 October describing a campaign it names Blinder Tunnel, targeting critical infrastructure in Iraq and attributed to an Iranian state-aligned activity cluster tracked as CL-STA-1178. Per the published research and the secondary summaries circulating from it, operators approached targets posing as recruiters for Dubai Airports; the infection chain ran through a fake job assessment, a coding test that executed malware on being opened in Visual Studio; and command-and-control was hosted on GitHub. The Files has not independently verified the victim sector, the number of targets, dwell time or whether Unit 42 links CL-STA-1178 to any previously named Iranian group. Those are the facts that determine whether this is a footnote or a campaign of consequence, and they are not yet established here.
The attribution tier matters and is routinely lost in re-reporting. Unit 42’s “CL-STA-” prefix denotes a clustered, state-backed activity set that the vendor has not merged into a named group — a deliberately lower confidence rung than an APT designation. This is vendor attribution, not government attribution: no state has publicly named an actor for Blinder Tunnel, and “Iranian state-aligned” is the researchers' formulation, not a finding of record. The social-engineering lure is the detail with regional weight. Impersonating a Gulf employer to reach Iraqi infrastructure professionals is a read on where those professionals want to work — an aspiration-shaped pretext rather than a technical one, and cheaper to run than any exploit in the chain.
Assessment: Watch what happens to the hedge. Vendor clusters with provisional identifiers tend to arrive in general coverage three days later as “Iranian hackers,” with the conditional stripped and the cluster ID promoted to a group name. Nothing in the published research supports that upgrade, and readers should treat any version of this story that drops CL-STA-1178 in favour of a familiar APT label as having added a claim the researchers did not make. The more durable point is operational: GitHub as C2 and a Visual Studio project as the detonator are commodity tradecraft, available to anyone. The pretext — a Gulf aviation employer, aimed at Iraq — is the part that required local knowledge.