News

Iranian Hackers Posed as Dubai Airports Recruiters and Hid Malware in a Coding Test That Fired When Opened

A fake Dubai Airports hiring process lured an engineer in Iraq's critical infrastructure sector into opening a rigged Visual Studio project. The malware ran before a single line was compiled.

Iranian Hackers Posed as Dubai Airports Recruiters and Hid Malware in a Coding Test That Fired When Opened

Someone working in Iraq's critical infrastructure sector, most likely a software engineer, thought they were applying for a job at Dubai Airports. They got an HR questionnaire, a careers portal and finally a coding test. The test was the attack, and it went off the moment the project was opened.

Palo Alto Networks' Unit 42 detailed the operation on Tuesday, attributing it to an Iranian state-aligned group it tracks as CL-STA-1178. The researchers call it "Blinder Tunnel," after the Peaky Blinders branding the attackers stamped across their GitHub accounts (one repository even embedded the show's theme song) and the malware's knack for tunneling through networks.

A con built in two acts

Infrastructure was staged as early as November 2025, and the operation went live in late March 2026. The first step was patient. An installer called "Dubai Airport Careers" dropped an offline imitation careers portal, complete with login credentials from the fake recruiters and a 10-question HR questionnaire. It did nothing malicious at all. It existed only to earn trust.

In April came the payload: DubaiAirport_Carrers_IT_Test.zip, misspelling included. Inside was a Visual Studio project and a personalized Readme asking the candidate to open a C# Flight Management System and fix a deliberately broken loop.

Nobody had to fix anything. The rigged FlightManager.csproj abused the background evaluation Visual Studio runs as soon as a project opens, so the malware launched before any code compiled.

From there the chain got quiet and clever. It copied files into a fake RuntimeBrokers folder, launched a renamed, Microsoft-signed Visual Studio host as RuntimeBroker.exe, hijacked it through AppDomainManager configuration, and switched off the .NET Event Tracing for Windows that security tools depend on. Then it sideloaded ShelbyLoader V2.

Commands hidden in GitHub issues

The loader fingerprinted the machine, checked for virtual machines, set registry persistence and talked to its operators through GitHub's API, uploading host identifiers and polling for commands. If that channel failed, it fell back to encrypted instructions hidden in HTML comments inside GitHub issues.

It then loaded two more tools. ShelbyC2 V2 runs PowerShell commands without ever launching PowerShell.exe. Blackwood wraps the open-source Chisel tool in memory to open encrypted tunnels and a reverse SOCKS proxy, a path deeper into the victim's network.

Fake job pipelines are a well-worn route in. North Korea's Contagious Interview crew has run the same playbook for years and recently moved to fake Mac installers. What stands out here is the patience of a decoy stage that does nothing but build rapport.

Who is behind it

Unit 42 assesses with high confidence that the activity is Iranian-nexus, based on infrastructure overlaps, Iranian hosting, regional targeting and a sloppy slip: metadata in a Peaky Blinders audio file pointing to an Iranian music site. Overlaps with known groups such as Screening Serpens and Agent Serpens were only low confidence, not enough to pin it on either.

The same infrastructure ran a credential-harvesting campaign against an Israeli entity in May and June, using war-themed lures and fake Google login pages. The cluster has previously hit telecom and aviation organizations in Iraq, Israel and the UAE, and Unit 42 says this is the first report tying that earlier activity, including what Elastic Security Labs dubbed "The Shelby Strategy" against an Iraqi telecom, into one tracked group.

Unit 42 found no evidence that Dubai Airports' own systems were compromised, and GitHub has taken the malicious infrastructure down.

Some offers on this page may be paid placements or contain affiliate links.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free