Image: Palo Alto Networks Unit 42
An Iranian-aligned threat actor posed as Dubai Airports recruiters and sent a booby-trapped coding test to a likely software engineer in Iraq. The targeted campaign focused on critical infrastructure, while researchers found no evidence that Dubai Airports itself was breached.
A convincing recruitment trap
Palo Alto Networks Unit 42 tracked the activity as CL-STA-1178 and named the March 2026 operation “Blinder Tunnel.” Researchers said infrastructure for the campaign had been staged as early as November 2025.The approach began with a fake Dubai Airports careers portal and questionnaire. A later stage delivered DubaiAirport_Carrers_IT_Test.zip, a personalized Visual Studio coding assessment that instructed the recipient to find and fix a simple C# bug.
Opening the project was enough
The archive contained a malicious .csproj configuration file. Visual Studio’s normal background project checks ran the attacker’s instructions as soon as the project was opened, copying malware into %LOCALAPPDATA%\Microsoft\RuntimeBrokers and launching RuntimeBroker.exe.The chain then used AppDomainManager hijacking and DLL sideloading—techniques that make trusted applications load attacker-controlled code. It also attempted to disable Event Tracing for Windows, a Windows activity-recording feature used by some security tools; this could weaken detection of the attack, not remove every layer of PC protection.
GitHub used for remote control
The resulting ShelbyLoader V2 malware established persistence, profiled the infected computer and contacted attacker-controlled GitHub resources for commands and additional payloads. GitHub issues provided a fallback channel if the primary repository or access token stopped working.GitHub removed the malicious infrastructure identified during the investigation. Unit 42 also linked operational mistakes in this campaign to conflict-themed Google Drive credential lures aimed at an Israeli entity in May and June 2026.
What developers should do
- Do not open unsolicited Visual Studio projects on a work PC, even when the sender presents the archive as a job assessment.
- If you opened DubaiAirport_Carrers_IT_Test.zip, ask your security team to inspect %LOCALAPPDATA%\Microsoft\RuntimeBrokers and investigate any RuntimeBroker.exe launched from that folder.
- Organizations should monitor trusted programs loading unusual DLL files from outside standard system directories, which Unit 42 recommends for spotting this sideloading behavior.