Iranian Hackers Masquerade as Dubai Airports in Sophisticated Attack on Iraq’s Infrastructure

Security analysts have uncovered a multi-stage campaign by Iranian state-aligned hackers that uses a fake recruitment funnel to infiltrate Iraqi critical infrastructure. The operation—dubbed “Blinder Tunnel”— tricks developers with a bogus Dubai Airports coding assessment, which in reality delivers stealthy persistence, remote access, and network tunneling tools. The first signs of planning emerged in late 2025, with active deployment starting in March 2026.  

The Deceptive Job Lure

The hackers’ process starts simple yet cunning: attackers built a credible offline careers portal, impersonating Dubai Airports’ IT division. Targets are led through a rudimentary HR form, nothing more at first to earn trust. Then they’re handed a development test—presented as a standard take-home assignment. The compressed Visual Studio project appears harmless: it asks candidates to fix a loop inside a “Flight Management System” module.  

That moment of trust is where the attackers strike. Hidden within the project file is a weaponized component. Once opened, it triggers a masqueraded executable—RuntimeBroker.exe—via Visual Studio’s background processes, before any code is built or run. A tricked configuration sets up AppDomainManager hijacking, designed to run malicious code early and suppress telemetry that might alert security teams. The tool then uses DLL sideloading to load a loader dubbed ShelbyLoader V2—effectively implementing the first stage of the compromise.  

Escalation, Covert Channels, and Tunneling

Once foothold is established, the campaign pivots to long-term control: ShelbyLoader V2 writes itself into registry auto-start entries, profiles infected machines, and communicates with attacker infrastructure using GitHub’s API. If that channel gets blocked, it can fall back to encrypted data hidden inside GitHub issue comments.  

More dangerous tools are also deployed. A component called Blackwood—essentially a wrapper for Chisel—is loaded in memory. It enables encrypted tunnels and a reverse SOCKS proxy, allowing operators to move from the compromised developer’s workstation deeper into network infrastructure. Analysts tied the cluster to Iran based on infrastructure overlap, targeting patterns, and a slip-up—a piece of audio file metadata that linked to a domain historically used by Iranian actors.  

What’s at Risk & What Defenders Should Do

The campaign highlights just how sensitive developer environments have become. Something as routine as opening a project file can serve as a launchpad for serious intrusion. Experts warn that suspicious developer test invitations, unexpected Visual Studio project files, unusual msbuild.exe activity, and strange .NET configuration changes should all trigger investigation.  

As immediate defense measures, organizations are urged to verify job-test assignments through independent channels, segment build environments, reset exposed credentials, enable phishing-resistant multi-factor authentication, harden detection for signed binaries that load unsigned or off-path DLLs, and watch for anomalous GitHub API usage.  

Indicators of compromise include a list of specific SHA-256 hashes tied to malicious archives, project files, loaders, DLLs, and infrastructure endpoints. Defenders can use these to detect or respond to instances of this attack.  

Over the long term, this campaign exemplifies how actor tradecraft is evolving: the building blocks of a compromise are hidden in what would normally be trusted tools, inactive until activated. Defender response must shift from perimeter hardening to scrutinizing inside build systems—and knowing that developer workflows themselves can be weaponized. Watch closely for increased use of developer-targeted lures and fallback C2 mechanisms via innocuous platforms.