Full Report
Unit 42 has discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign we call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging that…
Analysis Summary
# Threat Actor: CL-STA-1178
## Attribution & Identity
* **Actor Identification:** CL-STA-1178 is an Iranian state-aligned threat actor.
* **Known Aliases:** Currently tracked by Unit 42 as CL-STA-1178.
* **Known Associations:** Identified as having an "Iranian-nexus." The actor uses branding and infrastructure naming conventions inspired by the British crime drama *Peaky Blinders*.
## Activity Summary
* **Blinder Tunnel Campaign (March 2026):** A campaign targeting Iraqi critical infrastructure. Staging for this operation was observed as early as November 2025.
* **Dubai Airports Masquerade:** The actor has recently been observed masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets.
## Tactics, Techniques & Procedures
* **Social Engineering:** Posing as IT departments (e.g., Dubai Airports) to deliver malicious payloads under the guise of "coding challenges."
* **Malware Tunneling:** Use of custom malware with advanced tunneling capabilities to maintain access and bypass network security.
* **Themed Branding:** Naming command-and-control (C2) infrastructure components after *Peaky Blinders* branding and embedding the show's theme song into the malware code.
* **Infrastructure Staging:** Long-term preparation of infrastructure (up to 4 months prior to active campaigns).
## Targeting
* **Sectors:** Critical Infrastructure, Information Technology.
* **Geography:** Iraq (primary focus of the Blinder Tunnel campaign), United Arab Emirates (Dubai-themed masquerade).
* **Victims:** High-value targets (HVTs) and Iraqi critical infrastructure entities.
## Tools & Infrastructure
* **Malware:** Custom tunneling malware (referred to as "Blinder Tunnel" related tools).
* **Infrastructure:**
* C2 nodes named after *Peaky Blinders* characters/locations.
* Masquerading domains mimicking Dubai Airports IT department (e.g., [defanged] dubai-airports[.]com or similar variations).
## Implications
CL-STA-1178 demonstrates a high level of persistence and organizational sophistication, moving from infrastructure staging to active exploitation over several months. Their focus on Iraqi critical infrastructure suggests strategic regional objectives aligned with Iranian state interests. The use of niche cultural themes (*Peaky Blinders*) serves as a unique identifier for tracking their evolving operations.
## Mitigations
* **Email Security:** Implement rigorous filtering for incoming attachments, especially those framed as "coding challenges" or "technical assessments" from external entities.
* **Identity Verification:** Establish out-of-band verification processes for communications purportedly from large infrastructure hubs like Dubai Airports.
* **Network Monitoring:** Monitor for unusual tunneling protocols or unauthorized persistent connections to external IPs.
* **Endpoint Detection:** Deploy EDR solutions to identify the execution of trojanized development tools or coding environments.