SOC Prime Bias: Critical

08 Oct 2026 06:33 UTC

Blinder Tunnel Campaign Analysis: Tactics, Techniques, and Infrastructure

Author Photo
SOC Prime Team linkedin icon Follow
Blinder Tunnel Campaign Analysis: Tactics, Techniques, and Infrastructure
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

An Iranian state-aligned threat actor is conducting the Blinder Tunnel campaign against critical infrastructure organizations in the Middle East. The attackers rely on social engineering, impersonating Dubai Airports to distribute weaponized Visual Studio projects. These projects abuse trusted developer tools to deploy custom malware, including ShelbyLoader V2 and Blackwood tunneling utilities, while using GitHub-based command-and-control infrastructure.

Investigation

Unit 42 researchers traced the activity from infrastructure preparation in late 2025 through active targeting observed in 2026. The investigation uncovered a multi-stage infection chain involving AppDomainManager hijacking and DLL sideloading. Malware analysis also revealed the use of GitHub APIs for C2 communication and dead-drop resolvers, along with thematic naming and branding inspired by Peaky Blinders.

Mitigation

Organizations should harden developer environments and monitor for suspicious execution of trusted utilities such as msbuild.exe. Enforcing strict DLL loading controls and detecting unexpected or non-standard DLLs within system directories can reduce attack exposure. Security teams should also deploy advanced endpoint protection capable of detecting in-memory execution and unauthorized PowerShell activity.

Response

When suspicious activity is detected, organizations should isolate affected endpoints and initiate credential resets. Security teams should examine endpoint detection and response (EDR) telemetry for abnormal process behavior, particularly signs of legitimate process hijacking. Investigators should also review unauthorized connections to public cloud services such as GitHub for unusual or non-standard traffic patterns.

Attack Flow

Detections

Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)

SOC Prime Team
07 Oct 2026

System Processes Execution from Untypical Paths (via process_creation)

SOC Prime Team
07 Oct 2026

Possible Github File Downloading Initiated By Unusual Process (via network_connection)

SOC Prime Team
07 Oct 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
07 Oct 2026

IOCs (HashSha256) to detect: Blinder Tunnel Campaign Analysis

SOC Prime AI Rules
07 Oct 2026

IOCs (SourceIP) to detect: Blinder Tunnel Campaign Analysis

SOC Prime AI Rules
07 Oct 2026

IOCs (DestinationIP) to detect: Blinder Tunnel Campaign Analysis

SOC Prime AI Rules
07 Oct 2026

Suspicious Activity from Phishing Domain cloud.g-drive.cam [Google Cloud Platform]

SOC Prime AI Rules
07 Oct 2026

Detection of Renamed Processes Leading to AppDomainManager Hijacking [Windows Process Creation]

SOC Prime AI Rules
07 Oct 2026

Detection of Blinder Tunnel Malicious Visual Studio Project [Windows File Event]

SOC Prime AI Rules
07 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary initiates a phishing campaign. A victim receives an email appearing to be a shared document from Google Cloud. When the victim clicks the link, their browser makes a GET request to https://cloud.g-drive.cam/login/auth. This request is captured by the corporate proxy, which should trigger the detection rule based on the presence of the malicious domain in the URL.

  • Regression Test Script:

    # Simulation script to trigger the detection rule by requesting the phishing domain.
    # This simulates a user clicking a link in a phishing email.
    
    $PhishingUrl = "https://cloud.g-drive.cam/auth/login?user=victim"
    Write-Host "Simulating connection to phishing domain: $PhishingUrl"
    
    try {
        # We use -ErrorAction SilentlyContinue because the domain doesn't actually exist, 
        # but the DNS request and the attempt to connect will generate the proxy log.
        Invoke-WebRequest -Uri $PhishingUrl -Method Get -UseBasicParsing -ErrorAction SilentlyContinue
        Write-Host "Connection attempt completed. Check SIEM for proxy logs."
    }
    catch {
        Write-Host "Connection failed as expected (domain likely non-existent), but telemetry should be generated."
    }
  • Cleanup Commands:

    # No permanent changes are made to the system. 
    # To clear local web cache if necessary:
    Clear-History
    Write-Host "Simulation cleanup complete. No artifacts left on host."