An Iranian state-aligned threat actor impersonated Dubai Airports recruiters to deliver weaponized coding assessments to software engineers.
The operation deployed ShelbyLoader V2 through a stealthy execution chain that abused legitimate Microsoft development tools and GitHub infrastructure.
Tracked as CL-STA-1178, the activity includes “Blinder Tunnel,” a campaign targeting Iraqi critical infrastructure beginning in March 2026.
The attackers initially distributed an Inno Setup installer named Dubai Airport Careers, which installed an offline recruitment portal.
Candidates received login credentials and completed a ten-question HR questionnaire.
This first application performed no observed exfiltration, network communication, or malicious execution.
Instead, it served as a credibility-building decoy before the attackers introduced the actual infection mechanism.
In April 2026, researchers identified DubaiAirport_Carrers_IT_Test.zip, a Visual Studio project archive presented as a recruitment assessment.
Its personalized Readme.md instructed the recipient to open a C# Flight Management System project, locate an intentionally flawed loop, and fix the bug.
The trap did not require completing the exercise. Opening the project could trigger malware execution before compilation.
The malicious .csproj file overrode the GetFrameworkPaths target invoked during Visual Studio background initialization. Its instructions copied concealed binaries into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launched RuntimeBroker.exe.
Unit42 Researchers assesses that, the Iranian nexus with high confidence, while emphasizing that it found no evidence of any compromise of Dubai Airports’ systems.
Microsoft’s MSBuild documentation describes the customizable targets and tasks underlying this abuse.
RuntimeBroker.exe was actually a renamed, Microsoft-signed Visual Studio hosting executable.
An accompanying configuration file redirected its startup behavior through AppDomainManager hijacking, a technique that forces trusted .NET applications to load attacker-controlled assemblies.
The configuration also included <etwEnable enabled="false"/>, potentially impairing .NET Event Tracing for Windows visibility.
DLL sideloading completed the chain by loading RuntimeBroker.dll, identified as ShelbyLoader V2, into the trusted process.
ShelbyLoader V2 fingerprinted infected hosts, checked for virtualization artifacts, and established persistence through a MicrosoftRuntime registry startup value.
Security teams can detect this masquerading activity by monitoring abnormal process behavior. Cortex XDR flagged this execution chain as high risk and blocked the threat.
Its persistence routine ran every 120 seconds, while its primary beacon operated every 63 seconds.
Using an embedded personal access token, the loader communicated with the peakyblinders-tm/myLic GitHub repository, uploading host identifiers and polling files for commands.
If authentication failed, it searched GitHub issues for encrypted instructions concealed inside HTML comments.
This fallback could supply replacement repository details and credentials.
The architecture extends the GitHub-based command-and-control documented in Elastic Security Labs’ The Shelby Strategy, which analyzed earlier SHELBY malware targeting an Iraqi telecommunications organization.
The loader decrypted ShelbyC2 V2 directly into memory. Its PsProxy.dll module executed PowerShell through System.Management.Automation.dll without launching PowerShell.exe.
A separate Blackwood loader reflectively loaded Chisel, enabling encrypted tunnels and reverse SOCKS access for internal-network pivoting.
Researchers connected the campaign to credential-harvesting activity against an Israeli entity in May–June 2026.
Attribution relied on infrastructure overlaps, Iranian hosting, regional targeting, and Iranian music-site metadata embedded in a Peaky Blinders-themed audio file.
GitHub removed the identified malicious infrastructure. Defenders should investigate unexpected DLL loads, altered .NET configuration files.
Developer-tool processes launching executables from user-writable directories, while correlating those events with unusual GitHub API traffic and registry startup changes across affected developer endpoints.
| File name | Description | SHA-256 |
|---|---|---|
DubaiAirport_Carrers_IT_Test.zip | Initial malicious archive | 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 |
FlightManager.csproj | Weaponized Visual Studio project file | f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 |
RuntimeBroker.dll | Primary RAT loader | 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…