Iranian Threat Actor Targets Critical Infrastructure in Iraq and Israel

Photo: U.S. Air Force photo by Airman 1st Class Jared Lovett / Wikimedia Commons

A threat actor affiliated with the Iranian regime impersonated the IT department of Dubai Airports to distribute malicious programming challenges aimed at hitting high-value targets across the Middle East.

According to a detailed report by Unit 42, this marks the first publication linking these separate attacks into a unified operation, assessed with very high confidence to be connected to an Iranian threat source. Tracked under the intelligence identifier CL-STA-1178, the activity includes an attack operation dubbed “Blinder Tunnel” that directly targeted critical infrastructure in Iraq in March 2026, following infrastructure preparation observed as early as November 2025.

The broader campaign’s name is derived from various infrastructure terms used by the attackers, alongside the advanced tunneling capabilities of the malware used to breach systems. The campaign expanded on the actor’s prior operations and deliberately adopted motifs from the British crime drama series “Peaky Blinders,” including dedicated infrastructure component names and the embedding of the show’s theme song directly inside the malware code.

Researchers discovered that the attackers established an initial foothold through a complex three-stage attack chain, involving the exploitation of legitimate csproj development files, AppDomainManager hijacking, and binary execution via DLL sideloading. These technical steps enabled the attackers to deploy custom malware named ShelbyLoader V2, which operated covertly against victim systems.

To blend into legitimate network traffic, the campaign abused GitHub’s API infrastructure for command-and-control (C2) communication by fetching decryption keys, downloading dedicated payloads, and utilizing the platform’s Issues feature as a resilient backup communication channel. The malicious GitHub infrastructure was taken down after being discovered.

The investigation was aided by a series of severe operational security (OPSEC) and cryptographic errors made by the attackers, including exposing attack tools in public repositories, careless mixing of phishing and tunneling infrastructure, and embedding incriminating metadata in the TV show’s theme song. These tactical errors linked Operation Blinder Tunnel to a concurrent campaign in which the same actor used conflict-themed Google Drive lures to harvest credentials from an Israeli entity in May and June 2026.

The threat actor, previously linked to Elastic Security Labs’ “The Shelby Strategy” campaign, routinely targets telecommunications, aviation, and critical infrastructure sectors in Iraq, Israel, and the United Arab Emirates. In Iraq, customized recruitment lures were developed for engineers, and the infrastructure remained dormant until its activation in March 2026.

The AppDomainManager technique is currently adopted by Iranian groups such as Screening Serpens to execute malicious payloads within trusted applications. The attackers also utilized the Chisel tunneling tool to bridge external infrastructure with compromised networks. Comprehensive protection against the attack is provided by Palo Alto Networks products, including Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Cortex XDR, and Cortex XSIAM, supported by Cortex AgentiX.