Date: 10/07/2026
Severity: High
Summary
An Iranian state-aligned threat actor impersonated the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. The activity, tracked as CL-STA-1178, includes a campaign dubbed “Blinder Tunnel.” Blinder Tunnel targeted Iraqi critical infrastructure in March 2026, with infrastructure staging observed as early as November 2025. The campaign was named after attacker infrastructure terminology and the malware’s tunneling capabilities. Analysts assess with high confidence that the activity is linked to an Iranian-nexus threat, connecting previously reported attacks into a broader campaign.
Indicators of Compromise (IOC) List
Domains/URLs | cloud.g-drive.cam googeldrive.cam drivegoogel.cam googelmeet.online meetonline.cam asdfafadafg.online https://github.com/peakyblinders-tm https://github.com/GreenBeret0 |
IP Address | 91.107.156.29 87.248.129.239 65.109.214.145 38.180.136.127 |
Hash | 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239
f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9
53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402
3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13
76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e
d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260
f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd
7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875
|
Registry Key | HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://github.com/GreenBeret0" or url like "https://github.com/GreenBeret0" or siteurl like "https://github.com/GreenBeret0" or domainname like "asdfafadafg.online" or url like "asdfafadafg.online" or siteurl like "asdfafadafg.online" or domainname like "drivegoogel.cam" or url like "drivegoogel.cam" or siteurl like "drivegoogel.cam" or domainname like "meetonline.cam" or url like "meetonline.cam" or siteurl like "meetonline.cam" or domainname like "cloud.g-drive.cam" or url like "cloud.g-drive.cam" or siteurl like "cloud.g-drive.cam" or domainname like "googelmeet.online" or url like "googelmeet.online" or siteurl like "googelmeet.online" or domainname like "googeldrive.cam" or url like "googeldrive.cam" or siteurl like "googeldrive.cam" or domainname like "https://github.com/peakyblinders-tm" or url like "https://github.com/peakyblinders-tm" or siteurl like "https://github.com/peakyblinders-tm" |
Detection Query 2 : | dstipaddress IN ("91.107.156.29","38.180.136.127","65.109.214.145","87.248.129.239") or srcipaddress IN ("91.107.156.29","38.180.136.127","65.109.214.145","87.248.129.239") |
Detection Query 3 : | sha256hash IN ("d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260","f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9","f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd","7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875","53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402","6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239","76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e","3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13")
|
Detection Query 4 : | datasourcename = "Windows Security" and eventtype = "4657" and objectname like "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime" |
Detection Query 5 : | technologygroup = "EDR" and objectname like "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime" |
Reference:
https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/