Skip to content
Operation Blinder Tunnel Targets Iraqi Critical Infrastructure

Operation Blinder Tunnel Targets Iraqi Critical Infrastructure

First seen 6 Oct 2026, 12:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 14:28 UTC
  • •Operation Blinder Tunnel targets Iraqi critical infrastructure using trojanized coding challenges.
  • •Attackers impersonated Dubai Airports IT to deliver malware, utilizing a Peaky Blinders theme.
  • •The campaign is linked to previous credential-harvesting efforts against an Israeli entity.

Palo Alto Networks' Unit 42 has identified a campaign dubbed 'Operation Blinder Tunnel', attributed to an Iranian state-aligned threat actor targeting critical infrastructure in Iraq. The attackers impersonated the Dubai Airports IT Department to deliver trojanized coding challenges, allowing for a multi-stage malware infection. The campaign is linked to previous credential-harvesting efforts against an Israeli entity and utilized a Peaky Blinders theme, embedding the show's theme song in the malware. The attack chain involved exploiting legitimate Windows developer files, hijacking AppDomainManager, and executing binaries via DLL sideloading. The malware, referred to as ShelbyLoader V2, communicated through GitHub's API for command-and-control purposes. GitHub has since taken down the associated malicious infrastructure. This campaign highlights the evolving tactics of Iranian-aligned threat actors in the region.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-01
Blinder Tunnel campaign launched
The Iranian-aligned threat actor began targeting Iraqi critical infrastructure through trojanized coding challenges.
Unit42.Paloaltonetworks
2026-05-01
Credential harvesting campaign against Israeli entity
The same threat actor leveraged conflict-themed Google Drive lures for credential harvesting.
Unit42.Paloaltonetworks
2026-10-06
Malicious infrastructure taken down
GitHub removed the malicious repositories associated with the Blinder Tunnel campaign.
Unit42.Paloaltonetworks

More articles in this cluster (5)

Following this threat?

Track Screening Serpens, ShelbyLoader V2 and Dubai Airports in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What methods were used in the attack?
The attackers exploited legitimate Windows developer files, hijacked AppDomainManager, and executed binaries through DLL sideloading.
Is this campaign still active?
Yes, the campaign is ongoing, with recent activity observed targeting Iraqi infrastructure.
What should organizations do to protect themselves?
Organizations should enhance their security posture by monitoring for suspicious activity and applying advanced threat detection measures.