A group of hackers aligned with Iranian state interests has deployed a sophisticated campaign targeting Iraqi critical infrastructure through a deceptive recruitment process. Dubbed 'Blinder Tunnel', this operation involved using a fake coding test as part of a non-existent Dubai Airports recruitment process to gain access to sensitive systems. The campaign, which began preparations in November 2025 and was launched in March 2026, targeted an Iraqi software engineer.

The attackers designed a fake offline recruitment portal, presenting a Visual Studio project as a job assessment. The project contained hidden malicious code that allowed the attackers to gain remote access and establish persistence. Researchers from Unit 42 identified the campaign as CL-STA-1178 and linked it to Iranian threat actors.

The attackers impersonated Dubai Airports IT staff, although no actual breach of Dubai Airports systems was detected. By using trusted development tools to execute malicious instructions, they capitalized on the familiarity and trust developers place in these environments. The campaign also utilized cloud services to obscure its traffic, enhancing its stealth.

The initial recruitment step involved an Inno Setup application that mimicked a careers site, requiring login credentials provided by the fictitious recruiters. This site did not immediately steal data or deploy malware, aiming instead to build trust. A subsequent file, DubaiAirport_Carrers_IT_Test.zip, contained a Visual Studio project that launched the attack as soon as it was opened.

The malicious code executed in the background, creating a deceptive folder and launching unauthorized executables before any actual developer activity occurred. The attackers further hijacked system processes to ensure their code ran undetected, disabling certain Windows telemetry features to evade detection.

The campaign employed DLL sideloading to leverage legitimate processes to load malicious code. This method allowed persistent access and profile gathering of the host machine, with communications routed through GitHub’s API. Though GitHub has removed the identified attacker infrastructure, the operation highlights the need for vigilance against such sophisticated threats.

Additionally, the research linked other credential-harvesting activities to the same cluster of attacks, emphasizing the broader implications of this campaign. Organizations are advised to enhance their security measures by verifying job-related communications, isolating suspicious systems, and employing robust authentication methods.