March 2026: Unit 42 identified a targeted campaign, Blinder Tunnel, that activated dormant infrastructure staged as early as November 2025 to compromise Iraqi critical infrastructure by delivering a trojanized coding assessment that executed the moment a developer opened a weaponized Visual Studio project file.
The three-step infection chain that runs before a build
Unit 42 mapped a precise three-step attack chain that let the operator execute code without an explicit compile or user-run binary. The sequence began with a weaponized Microsoft Visual Studio .csproj file, abused to run attacker-defined XML targets during Visual Studio’s design-time build (GetFrameworkPaths). That initial step dropped and launched a renamed Microsoft hosting process, RuntimeBroker.exe, which the attackers then manipulated via AppDomainManager hijacking to hand execution to a malicious runtime manager. The final phase used DLL sideloading — loading RuntimeBroker.dll (ShelbyLoader V2) into the trusted host — to run the payload in a trusted process and disable a key telemetry mechanism (), reducing visibility into in-memory behavior.
Modular toolset: ShelbyLoader V2, ShelbyC2 V2, Blackwood and Chisel
The campaign employed a layered, .NET-centric toolset. RuntimeBroker.dll (ShelbyLoader V2) acted as the loader, creating persistence via HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime and beaconing every 63 seconds to a GitHub-hosted command-and-control. ShelbyLoader V2 fingerprinted hosts, performed anti-analysis checks (WMI, processes, registry, hardware), and retrieved second-stage binaries encrypted with AES-CBC.
ShelbyC2 V2 (loaded as RuntimeBrokerApi.dll) served as the primary remote access tool and used PsProxy.dll — an in-memory PowerShell execution engine that hooks System.Management.Automation.dll — to run scripts without spawning PowerShell.exe. For tunneling and lateral movement the operators deployed Blackwood: a .NET loader that embedded an encrypted Chisel DLL (the open-source tunneling utility), decrypted it (using a hard-coded passphrase and AES-256-CBC) and established reverse SOCKS proxies. One discovered configuration directed infected hosts to 91.107.156[.]29 with a reverse SOCKS endpoint R:0.0.0.0:10999:socks.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleLiving off the cloud: GitHub APIs, dead-drop resolvers, and operational mistakes
To blend C2 traffic with legitimate enterprise activity, attackers misused GitHub APIs. ShelbyLoader V2 attempted to authenticate with a hard-coded GitHub Personal Access Token and uploaded a Base64 machine fingerprint to /{{machineId}}/Lic.txt in the peakyblinders-tm/myLic repository, then polled /{{machineId}}/Inf.txt for Base64-encoded commands. If primary access failed (HTTP 401) or rate limits triggered HTTP 403, the malware turned to a dead-drop resolver using GitHub Issues Search API: it located issues matching yyyymmdd-formatted queries, extracted ciphertext hidden inside HTML comments (), and decrypted AES-256-CBC blobs using a key derived from the date and machineId to rotate owners, repos, and tokens.
The operators’ operational security errors were decisive for investigators: attackers left music metadata (COMMENT field referencing MusicDel[.]ir) in an uploaded MP3 and exposed tools and test telemetry in public repositories under peakyblinders-tm. GitHub removed the malicious repos identified by Unit 42, and Palo Alto Networks shared these findings with the Cyber Threat Alliance to speed protections.
Operational testing, phishing lures, and the campaign footprint
Unit 42 observed staging and validation activity beginning Nov. 18, 2025, with dead-drop resolver tests on GitHub comments. The active recruitment lure started as an Inno Setup installer named Dubai Airport Careers that presented an offline career portal and a tailored 10-question questionnaire to build trust. A later stage delivered DubaiAirport_Carrers_IT_Test.zip, a Visual Studio project that triggered the weaponized .csproj on open. Multiple artifacts and VirusTotal submissions traced parts of the operation to Iraq and to additional credential-harvesting activity targeting an Israeli entity in May–June 2026 using Google-themed typosquatted domains (cloud.g-drive[.]cam, googeldrive[.]cam, drivegoogel[.]cam, googelmeet[.]online, meetonline[.]cam).
Unit 42 cataloged key files and hashes (for example, FlightManager.csproj f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9; RuntimeBroker.dll 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402) and identified additional infrastructure IPs used by Blackwood and tunneling endpoints (87.248.129[.]239; 65.109.214[.]145; 38.180.136[.]127).
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Prioritize monitoring of developer-tool behavior (design-time builds, msbuild.exe targets, unexpected .csproj XML targets), watch for nonstandard DLL loads and abnormal GitHub API traffic, and hunt for in-memory PowerShell activity that does not spawn PowerShell.exe. Unit 42 noted Cortex XDR flagged the root .slnx file and blocked execution in at least one instance.
- Policymakers and regulators: The campaign underscores the need to consider protections around code-repository abuse and to encourage platform takedown coordination; GitHub removed the malicious infrastructure after identification, and findings were shared with the Cyber Threat Alliance.
- Affected enterprises and procurement leaders (telecommunications, aviation, critical infrastructure): Treat recruitment lures as high-risk phishing vectors, verify recruiter provenance, and secure developer environments from unvetted sample projects and third-party archives. Unit 42 recommends hardening developer workstations and monitoring cloud platform traffic for living-off-the-cloud patterns.
Unit 42 tracks the activity as CL-STA-1178 and assesses with high confidence that it aligns with an Iranian state-aligned threat actor, citing Iranian-hosted infrastructure, Persian-language domain links, MusicDel[.]ir metadata, and a regional victimology focused on Iraq, the UAE and Israel. The campaign’s combination of weaponized developer tooling, GitHub-based C2 dead-drops, an in-memory PowerShell proxy and a custom Chisel-based tunneling wrapper demonstrates an operator willing to invest time in staging and testing yet still leaving forensics that reveal both technique and intent.
For the full technical write-up and indicators, see the original Unit 42 report: https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/




