Blinder Tunnel Campaign Targets Iraqi Infrastructure

    Date: 10/07/2026

    Severity: High

    Summary

    An Iranian state-aligned threat actor impersonated the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. The activity, tracked as CL-STA-1178, includes a campaign dubbed “Blinder Tunnel.” Blinder Tunnel targeted Iraqi critical infrastructure in March 2026, with infrastructure staging observed as early as November 2025. The campaign was named after attacker infrastructure terminology and the malware’s tunneling capabilities. Analysts assess with high confidence that the activity is linked to an Iranian-nexus threat, connecting previously reported attacks into a broader campaign.

    Indicators of Compromise (IOC) List

    Domains/URLs

    cloud.g-drive.cam

    googeldrive.cam

    drivegoogel.cam

    googelmeet.online

    meetonline.cam

    asdfafadafg.online

    https://github.com/peakyblinders-tm

    https://github.com/GreenBeret0

    IP Address

    91.107.156.29

    87.248.129.239

    65.109.214.145

    38.180.136.127

    Hash

    6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239

    f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9

    53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402

    3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13

    76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e

    d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260

    f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd

    7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875

    Registry Key

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://github.com/GreenBeret0" or url like "https://github.com/GreenBeret0" or siteurl like "https://github.com/GreenBeret0" or domainname like "asdfafadafg.online" or url like "asdfafadafg.online" or siteurl like "asdfafadafg.online" or domainname like "drivegoogel.cam" or url like "drivegoogel.cam" or siteurl like "drivegoogel.cam" or domainname like "meetonline.cam" or url like "meetonline.cam" or siteurl like "meetonline.cam" or domainname like "cloud.g-drive.cam" or url like "cloud.g-drive.cam" or siteurl like "cloud.g-drive.cam" or domainname like "googelmeet.online" or url like "googelmeet.online" or siteurl like "googelmeet.online" or domainname like "googeldrive.cam" or url like "googeldrive.cam" or siteurl like "googeldrive.cam" or domainname like "https://github.com/peakyblinders-tm" or url like "https://github.com/peakyblinders-tm" or siteurl like "https://github.com/peakyblinders-tm"

    Detection Query 2 :

    dstipaddress IN ("91.107.156.29","38.180.136.127","65.109.214.145","87.248.129.239") or srcipaddress IN ("91.107.156.29","38.180.136.127","65.109.214.145","87.248.129.239")

    Detection Query 3 :

    sha256hash IN ("d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260","f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9","f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd","7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875","53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402","6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239","76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e","3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4657" and objectname like "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime"

    Detection Query 5 :

    technologygroup = "EDR" and objectname like "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftRuntime"

    Reference: 

    https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/              


    Tags

    MalwareThreat ActorIranIraqInformation TechnologyTrojanCritical Infrastructure

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags