Iranian hackers have launched a sophisticated campaign using a fabricated recruitment process to compromise Iraqi critical infrastructure. The operation, called ‘Blinder Tunnel,’ involved a fake coding test, which served as a covert entry point for remote access and network persistence. This deceptive tactic highlights the increasing vulnerability of developer environments to cyber threats.
Details of the Cyber Campaign
Initiated in March 2026, the campaign targeted software engineers in Iraq, masquerading as a recruitment assessment for Dubai Airports. Victims were lured with an offline careers portal and a Visual Studio project, falsely presented as a job application task. The operation, identified as CL-STA-1178 by Unit 42 researchers, is strongly believed to be linked to Iranian state-sponsored actors.
Despite impersonating Dubai Airports’ IT personnel, no evidence points to any breach of the airport’s systems. This tactic underscores the threat actors’ reliance on deception to gain unauthorized access to sensitive networks. The campaign cleverly disguised malicious activities within seemingly benign developer tools, allowing attackers to execute their code before victims even realized the threat.
Technical Aspects of the Attack
The attackers initiated contact through a local imitation of the Dubai Airport Careers portal, requesting credentials and presenting a non-malicious HR form. This initial step was designed to build trust. The subsequent archive, DubaiAirport_Carrers_IT_Test.zip, contained a Visual Studio project, which, once opened, triggered the attack. The project file was weaponized to exploit Visual Studio’s evaluation process, executing malicious code without user intervention.
The attackers modified configuration files to hijack the AppDomainManager, bypassing typical security checks and executing their code covertly. This method of attack reflects a broader trend in Iranian hacking operations, which increasingly utilize sophisticated techniques to evade detection and maintain persistence within targeted systems.
Defensive Measures and Recommendations
Security researchers recommend that organizations closely monitor unusual activities such as unexpected msbuild.exe executions and changes to .NET configurations. Security teams should also verify the legitimacy of job-related files independently and employ phishing-resistant multi-factor authentication.
In response to this threat, GitHub has removed the malicious infrastructure used by the attackers. Nevertheless, the campaign’s complexity, involving DLL sideloading and the deployment of various backdoor tools, highlights the need for vigilant and proactive cybersecurity measures to protect against such intricate threats.
The incident not only exposes the tactics of Iranian hackers but also serves as a reminder of the evolving nature of cyber threats. As attackers employ more sophisticated methods, organizations must enhance their defenses to safeguard critical infrastructure from similar intrusions in the future.
