Cybersecurity Research

Fake Dubai Airports IT Staff Used Trojanized Coding Tests to Target Critical Infrastructure

Unit 42 · 6 Oct 2026
Key Takeaway Treat unsolicited technical tests or job-style tasks from people claiming to be IT staff as suspicious, verify the sender through a separate trusted channel, and never run code from unverified sources on a work device.

Researchers at Unit 42 have uncovered a campaign by an Iranian state-aligned threat actor, tracked as CL-STA-1178, that posed as the Dubai Airports IT department. The attackers delivered trojanized coding challenges to high-value targets. One part of the activity, named "Blinder Tunnel", targeted Iraqi critical infrastructure in March 2026, after the attackers began staging infrastructure as early as November 2025. Unit 42 assesses with high confidence that the activity is linked to Iran.

The attackers gained an initial foothold through a three-step attack chain, which let them deploy custom malware that Unit 42 calls ShelbyLoader V2. To blend in with normal cloud traffic, they misused GitHub's API infrastructure for command-and-control communication, using repositories to manage their malware. GitHub has since taken down the malicious infrastructure Unit 42 identified. The campaign also carried a "Peaky Blinders" theme, with infrastructure named after the TV drama and its theme song embedded in the malware.

Unit 42 says the attackers made operational security and cryptographic mistakes, which helped link Blinder Tunnel to a separate campaign. In that one, the same actor used conflict-themed Google Drive lures to harvest credentials from an Israeli entity in May and June 2026. This is the first report to connect these separate attacks as related activity.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Unit 42, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.