UNIT 42 describes a multifaceted campaign, nicknamed Blinder Tunnel, run by an Iranian state-aligned threat actor. Beginning as a social-engineering drive in early 2026, the operation impersonated Dubai Airports’ IT department to target a software engineer in Iraq, delivering a trojanised Visual Studio coding challenge that laid the groundwork for deeper intrusion.
The attackers leveraged a three-step infection chain: weaponising a malicious Visual Studio project file (.csproj), hijacking AppDomainManager, and then performing DLL sideloading to execute a custom loader and later a backdoor. The campaign’s core malware, ShelbyLoader V2, operated as a loader and persistence mechanism, while ShelbyC2 V2 acted as the primary backdoor.
To blend in with legitimate traffic, the group used GitHub’s API as a command-and-control channel, including a dead-drop fallback via GitHub Issues when primary channels were blocked.
The attackers’ toolset grew to include Blackwood, a in-memory Chisel tunneling wrapper, and PsProxy[.]dll, a PowerShell proxy module, all orchestrated through a GitHub-hosted C2 network.
Evidence presented includes named payloads (DubaiAirport_Carrers_IT_Test.zip, FlightManager[.]csproj, RuntimeBroker[.]dll, PsProxy[.]dll, Blackwood[.]dll and configurations), IP addresses and phishing domains linked to the campaign, and detailed descriptions of the obfuscated .NET components and configuration alterations used to disable security monitoring.
Unit 42 notes that GitHub infrastructure has since been taken down and highlights how this living-off-the-cloud approach enabled encryption tunnels and lateral movement. Practical responses focus on monitoring developer environments, cloud traffic anomalies, and the specific lures and payloads described, supported by references to Cortex XDR, WildFire, and related protections.