Blinder Tunnel Campaign Analysis: Tactics, Techniques, and Infrastructure
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
An Iranian state-aligned threat actor is conducting the Blinder Tunnel campaign against critical infrastructure organizations in the Middle East. The attackers rely on social engineering, impersonating Dubai Airports to distribute weaponized Visual Studio projects. These projects abuse trusted developer tools to deploy custom malware, including ShelbyLoader V2 and Blackwood tunneling utilities, while using GitHub-based command-and-control infrastructure.
Investigation
Unit 42 researchers traced the activity from infrastructure preparation in late 2025 through active targeting observed in 2026. The investigation uncovered a multi-stage infection chain involving AppDomainManager hijacking and DLL sideloading. Malware analysis also revealed the use of GitHub APIs for C2 communication and dead-drop resolvers, along with thematic naming and branding inspired by Peaky Blinders.
Mitigation
Organizations should harden developer environments and monitor for suspicious execution of trusted utilities such as msbuild.exe. Enforcing strict DLL loading controls and detecting unexpected or non-standard DLLs within system directories can reduce attack exposure. Security teams should also deploy advanced endpoint protection capable of detecting in-memory execution and unauthorized PowerShell activity.
Response
When suspicious activity is detected, organizations should isolate affected endpoints and initiate credential resets. Security teams should examine endpoint detection and response (EDR) telemetry for abnormal process behavior, particularly signs of legitimate process hijacking. Investigators should also review unauthorized connections to public cloud services such as GitHub for unusual or non-standard traffic patterns.
Attack Flow
Detections
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)
System Processes Execution from Untypical Paths (via process_creation)
Possible Github File Downloading Initiated By Unusual Process (via network_connection)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: Blinder Tunnel Campaign Analysis
IOCs (SourceIP) to detect: Blinder Tunnel Campaign Analysis
IOCs (DestinationIP) to detect: Blinder Tunnel Campaign Analysis
Suspicious Activity from Phishing Domain cloud.g-drive.cam [Google Cloud Platform]
Detection of Renamed Processes Leading to AppDomainManager Hijacking [Windows Process Creation]
Detection of Blinder Tunnel Malicious Visual Studio Project [Windows File Event]
Simulation Execution
-
Attack Narrative & Commands: The adversary initiates a phishing campaign. A victim receives an email appearing to be a shared document from Google Cloud. When the victim clicks the link, their browser makes a GET request to
https://cloud.g-drive.cam/login/auth. This request is captured by the corporate proxy, which should trigger the detection rule based on the presence of the malicious domain in the URL. -
Regression Test Script:
# Simulation script to trigger the detection rule by requesting the phishing domain. # This simulates a user clicking a link in a phishing email. $PhishingUrl = "https://cloud.g-drive.cam/auth/login?user=victim" Write-Host "Simulating connection to phishing domain: $PhishingUrl" try { # We use -ErrorAction SilentlyContinue because the domain doesn't actually exist, # but the DNS request and the attempt to connect will generate the proxy log. Invoke-WebRequest -Uri $PhishingUrl -Method Get -UseBasicParsing -ErrorAction SilentlyContinue Write-Host "Connection attempt completed. Check SIEM for proxy logs." } catch { Write-Host "Connection failed as expected (domain likely non-existent), but telemetry should be generated." } -
Cleanup Commands:
# No permanent changes are made to the system. # To clear local web cache if necessary: Clear-History Write-Host "Simulation cleanup complete. No artifacts left on host."