Skip to content

Security1 publisher2 min readPublished

Unit 42 ties fake coding challenges from Dubai Airports to an Iranian campaign in Iraq

Palo Alto's Unit 42 says an Iranian state-aligned actor it tracks as CL-STA-1178 posed as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Its report ties attacks other vendors reported one at a time into one campaign that hit Iraqi critical infrastructure in March 2026.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Initial access runs a three-step chain: a weaponized .csproj build file, AppDomainManager hijacking, then DLL sideloading to establish covert access.
  • Since the March launch the lures have evolved toward recruitment, aimed specifically at Iraqi software developers and engineers.
  • Operational security slips, including metadata embedded in the Peaky Blinders theme song, linked the campaign to a May-June 2026 credential-harvesting run against an Israeli entity.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A coding challenge sent by a fake recruiter and a .csproj build file turn a developer's normal workflow into initial access, and the people targeted work inside critical-infrastructure operators.
  • capability Running command and control through GitHub's API and issues lets the traffic pass as ordinary cloud activity, so server blocklists and reputation checks miss it.
  • constraint A defender who saw one of these attacks alone was underrating a sustained Iranian operation; the single-cluster attribution lets them map the whole campaign instead of a one-off.
  • precedent AppDomainManager hijacking is spreading among Iranian groups, so this evasion step is likely to recur beyond this actor.

The infection starts with a file developers already trust. The attackers weaponized a .csproj file, the Microsoft project file that build tools read to compile software. [14][6] Processing the trojanized coding challenge triggers AppDomainManager hijacking, which forces a trusted Windows binary to run attacker code, and DLL sideloading then loads the custom malware Unit 42 calls ShelbyLoader V2. [6][7]

Command and control runs through GitHub. The malware pulls decryption keys and payloads from repositories, and falls back to GitHub issues when it needs a durable channel. [8] That traffic blends with ordinary developer activity on GitHub. GitHub removed the infrastructure Unit 42 flagged. [9]

The report says it is the first to connect attacks that other vendors described one at a time. [17] Unit 42 assesses with high confidence that the activity is Iranian-nexus, and the cluster was previously tracked by Elastic Security Labs as The Shelby Strategy. [5][18] The group brands its infrastructure after the television series "Peaky Blinders" and embedded the show's theme song in the malware. [12]

The branding helped investigators. Metadata inside that theme song, tools left on public repositories, and phishing infrastructure that shared hosts with tunneling infrastructure let Unit 42 tie Blinder Tunnel to a May-June 2026 operation that used conflict-themed Google Drive lures to harvest credentials from an Israeli entity. [10][11]

Staging infrastructure was visible as early as November 2025. It stayed dormant but operational until March 2026, roughly four months, when the attackers activated it against an individual in Iraq's critical infrastructure sector. [4][16] Targets span telecommunications, aviation and other critical entities across Iraq, Israel and the UAE. [13] Since March the lures have moved toward recruitment, aimed at Iraqi software developers and engineers. [2]

AppDomainManager hijacking is not unique to this group. Unit 42 says it is an emerging evasion technique that Iranian threat groups like Screening Serpens are also adopting. [15]

What to watch

  • Whether other vendors confirm Unit 42's single-actor attribution for attacks they reported separately.
  • Whether the recruitment lures expand beyond Iraqi developers to critical-infrastructure staff in other countries.
  • Fresh GitHub command-and-control infrastructure appearing after the takedown.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories