Unit 42 says an Iran-aligned actor it tracks as CL-STA-1178 used fake Dubai Airports IT recruitment lures to target Iraqi critical infrastructure in March 2026, after staging activity was seen as early as November 2025. Unit 42 says this is the first report to tie the scattered attacks together as one Blinder Tunnel campaign.
The intrusion chain abused Windows developer project files, AppDomainManager hijacking, and DLL sideloading to launch malware in memory, then used GitHub for command-and-control: repositories carried decryption keys and payloads, and GitHub issues served as a fallback channel. That makes the traffic look like ordinary developer-platform use instead of a dedicated malware server, which leaves fewer artifacts for file-based hunting.
For government and critical infrastructure teams, the lasting issue is not just the named malware but the control plane it hid inside: trusted cloud and engineering services can be turned into covert infrastructure. If those services are normal in your environment, this campaign shows they can also become the channel that stretches dwell time and blurs attribution.
Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure.