CL-STA-1178 is an Iranian state-aligned threat activity cluster targeting high-value organizations in the Middle East, including telecommunications, aviation and critical infrastructure entities in Iraq, Israel and the United Arab Emirates. Its activities include the Blinder Tunnel campaign and operations associated with the previously documented Shelby Strategy. The cluster has not been conclusively attributed to an established Iranian threat group. Blinder Tunnel targeted Iraqi critical infrastructure beginning in March 2026, following infrastructure preparation observed in November 2025. The attackers impersonated Dubai Airports IT recruiters, using an offline recruitment portal to build trust before delivering a trojanized Visual Studio coding assessment. Opening the project triggered malicious execution through Visual Studio design-time evaluation without requiring compilation. The execution chain combined AppDomainManager hijacking and DLL sideloading into a legitimate Microsoft hosting process. Dubai Airports' identity was used as a lure; no compromise of its systems was established. The cluster deployed ShelbyLoader V2 for host profiling, registry-based persistence and GitHub-based command-and-control. Encrypted instructions concealed in GitHub issue comments provided a fallback mechanism for updating command-and-control configuration. ShelbyC2 V2 supported command execution through an in-process PowerShell engine, avoiding a separate PowerShell process. Blackwood, a memory-resident wrapper for Chisel, provided encrypted tunneling and reverse SOCKS proxy access into compromised networks. Defense-evasion measures included .NET obfuscation, virtualization checks, disabling Event Tracing for Windows and in-memory payload loading. Related infrastructure supported a May–June 2026 credential-harvesting operation against an Israeli entity using Google-themed impersonation pages. Google Drive itself was not compromised or involved in delivering the attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 malware families attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian state-aligned activity cluster associated with the Blinder Tunnel campaign targeting Iraqi critical infrastructure in March 2026. Infrastructure staging was observed as early as November 2025. Analysts assess the Iranian-nexus attribution with high confidence. Blinder Tunnel is a campaign name, not an explicitly identified actor alias.
An assessed Iranian state-aligned activity cluster conducting the Blinder Tunnel campaign against Iraqi critical infrastructure. The attackers impersonated Dubai Airports recruiters and delivered a weaponized developer assessment to establish persistent remote access and network tunneling. Researchers also linked the cluster to credential-harvesting infrastructure targeting an Israeli entity in May and June 2026. Dubai Airports was impersonated; no compromise of its systems was identified.
An Iranian state-aligned activity cluster conducting targeted operations against telecommunications, aviation and critical infrastructure in Iraq, Israel and the UAE. Its Blinder Tunnel campaign used Dubai Airports recruitment impersonation and a weaponized Visual Studio coding challenge to target an Iraqi software engineer. Infrastructure overlaps also linked the cluster to a May–June 2026 credential-harvesting campaign against an Israeli entity. The report assesses Iranian attribution with high confidence but does not establish attribution to Screening Serpens or Agent Serpens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.