unit42 · Crawled Oct 8, 2026

Blinder Tunnel Campaign Targets Iraqi Infrastructure

18 IoCs 2 Actors
Read original article ↗

AI Summary

The Blinder Tunnel campaign, attributed to an Iranian state-aligned threat actor, targeted Iraqi critical infrastructure in March 2026 using a sophisticated social engineering lure impersonating Dubai Airports' IT department. The attack delivered trojanized Visual Studio projects that exploited .csproj files, AppDomainManager hijacking, and DLL sideloading to deploy custom malware including ShelbyLoader V2 and Blackwood, a Chisel-based tunneling tool. Command-and-control was conducted via GitHub repositories and issues, with fallback mechanisms using encrypted comments, while infrastructure reuse linked this activity to a parallel credential-harvesting campaign targeting Israel.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 18 extracted

Type Value Detail
SHA-256 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 Details →
SHA-256 f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 Details →
SHA-256 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 Details →
SHA-256 3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 Details →
SHA-256 76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e Details →
SHA-256 d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 Details →
SHA-256 f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd Details →
SHA-256 7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875 Details →
IP 91[.]107[.]156[.]29 Details →
IP 87[.]248[.]129[.]239 Details →
IP 65[.]109[.]214[.]145 Details →
IP 38[.]180[.]136[.]127 Details →
Domain cloud[.]g-drive[.]cam Details →
Domain googeldrive[.]cam Details →
Domain drivegoogel[.]cam Details →
Domain googelmeet[.]online Details →
Domain meetonline[.]cam Details →
Domain asdfafadafg[.]online Details →