Cyber Security News

Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2

An Iranian state-aligned threat actor impersonated Dubai Airports recruiters to deliver weaponized coding assessments to software engineers.

The operation deployed ShelbyLoader V2 through a stealthy execution chain that abused legitimate Microsoft development tools and GitHub infrastructure.

Tracked as CL-STA-1178, the activity includes “Blinder Tunnel,” a campaign targeting Iraqi critical infrastructure beginning in March 2026.

The attackers initially distributed an Inno Setup installer named Dubai Airport Careers, which installed an offline recruitment portal.

Candidates received login credentials and completed a ten-question HR questionnaire.

This first application performed no observed exfiltration, network communication, or malicious execution.

Instead, it served as a credibility-building decoy before the attackers introduced the actual infection mechanism.

In April 2026, researchers identified DubaiAirport_Carrers_IT_Test.zip, a Visual Studio project archive presented as a recruitment assessment.

Its personalized Readme.md instructed the recipient to open a C# Flight Management System project, locate an intentionally flawed loop, and fix the bug.

The trap did not require completing the exercise. Opening the project could trigger malware execution before compilation.

The malicious .csproj file overrode the GetFrameworkPaths target invoked during Visual Studio background initialization. Its instructions copied concealed binaries into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launched RuntimeBroker.exe.

Unit42 Researchers assesses that, the Iranian nexus with high confidence, while emphasizing that it found no evidence of any compromise of Dubai Airports’ systems.

Overview of the Blinder Tunnel campaign (Source : Unit42).

Microsoft’s MSBuild documentation describes the customizable targets and tasks underlying this abuse.

RuntimeBroker.exe was actually a renamed, Microsoft-signed Visual Studio hosting executable.

ShelbyLoader V2 Malware

An accompanying configuration file redirected its startup behavior through AppDomainManager hijacking, a technique that forces trusted .NET applications to load attacker-controlled assemblies.

Impersonated Dubai Airports career portal login page (Source : Unit42).

The configuration also included <etwEnable enabled="false"/>, potentially impairing .NET Event Tracing for Windows visibility.

DLL sideloading completed the chain by loading RuntimeBroker.dll, identified as ShelbyLoader V2, into the trusted process.

ShelbyLoader V2 fingerprinted infected hosts, checked for virtualization artifacts, and established persistence through a MicrosoftRuntime registry startup value.

Security teams can detect this masquerading activity by monitoring abnormal process behavior. Cortex XDR flagged this execution chain as high risk and blocked the threat.

Its persistence routine ran every 120 seconds, while its primary beacon operated every 63 seconds.

Using an embedded personal access token, the loader communicated with the peakyblinders-tm/myLic GitHub repository, uploading host identifiers and polling files for commands.

The infection chain as seen, detected and prevented by Cortex XDR (Source : Unit42).

If authentication failed, it searched GitHub issues for encrypted instructions concealed inside HTML comments.

This fallback could supply replacement repository details and credentials.

The architecture extends the GitHub-based command-and-control documented in Elastic Security Labs’ The Shelby Strategy, which analyzed earlier SHELBY malware targeting an Iraqi telecommunications organization.

The loader decrypted ShelbyC2 V2 directly into memory. Its PsProxy.dll module executed PowerShell through System.Management.Automation.dll without launching PowerShell.exe.

A separate Blackwood loader reflectively loaded Chisel, enabling encrypted tunnels and reverse SOCKS access for internal-network pivoting.

Researchers connected the campaign to credential-harvesting activity against an Israeli entity in May–June 2026.

Attribution relied on infrastructure overlaps, Iranian hosting, regional targeting, and Iranian music-site metadata embedded in a Peaky Blinders-themed audio file.

GitHub removed the identified malicious infrastructure. Defenders should investigate unexpected DLL loads, altered .NET configuration files.

Developer-tool processes launching executables from user-writable directories, while correlating those events with unusual GitHub API traffic and registry startup changes across affected developer endpoints.

IOCs

File nameDescriptionSHA-256
DubaiAirport_Carrers_IT_Test.zipInitial malicious archive6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239
FlightManager.csprojWeaponized Visual Studio project filef5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9
RuntimeBroker.dllPrimary RAT loader53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago