www.elastic.co Operation Blinder Tunnel Targets Iraqi Critical Infrastructure
Article Content
- •Operation Blinder Tunnel targets Iraqi critical infrastructure using trojanized coding challenges.
- •Attackers impersonated Dubai Airports IT to deliver malware, utilizing a Peaky Blinders theme.
- •The campaign is linked to previous credential-harvesting efforts against an Israeli entity.
Palo Alto Networks' Unit 42 has identified a campaign dubbed 'Operation Blinder Tunnel', attributed to an Iranian state-aligned threat actor targeting critical infrastructure in Iraq. The attackers impersonated the Dubai Airports IT Department to deliver trojanized coding challenges, allowing for a multi-stage malware infection. The campaign is linked to previous credential-harvesting efforts against an Israeli entity and utilized a Peaky Blinders theme, embedding the show's theme song in the malware. The attack chain involved exploiting legitimate Windows developer files, hijacking AppDomainManager, and executing binaries via DLL sideloading. The malware, referred to as ShelbyLoader V2, communicated through GitHub's API for command-and-control purposes. GitHub has since taken down the associated malicious infrastructure. This campaign highlights the evolving tactics of Iranian-aligned threat actors in the region.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Screening Serpens, ShelbyLoader V2 and Dubai Airports in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What methods were used in the attack?
Is this campaign still active?
What should organizations do to protect themselves?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…