Full Report
Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42.
Analysis Summary
# Threat Actor: Blinder Tunnel Campaign (Iran-nexus)
## Attribution & Identity
* **Identification:** The campaign is attributed to an **Iran-nexus** threat actor.
* **Aliases/Associations:** While a specific named group (e.g., APT34, MuddyWater) is not definitively assigned in this report, the activity shares overlaps with known Iranian state-sponsored behavior, specifically regarding the use of GitHub for C2 and targeting Middle Eastern critical infrastructure.
## Activity Summary
* **Campaign Name:** Blinder Tunnel.
* **Timeline:** Active throughout mid-to-late 2023 and early 2024.
* **Operations:** The actor utilized a sophisticated multi-stage infection chain beginning with social engineering lures (fake job recruitment) to deploy custom malware designed for intelligence collection and persistent access.
## Tactics, Techniques & Procedures
* **Initial Access:** Spear-phishing using job recruitment lures (T1566.001).
* **Lure Documents:** Use of a Windows Shortcut (LNK) file masquerading as a recruitment PDF for Dubai Airports.
* **Execution:** Use of `mshta.exe` to execute malicious HTA files (T1218.005).
* **Evasion:** Execution of PowerShell scripts in memory and use of legitimate cloud services (GitHub) for Command and Control (C2) to blend in with normal traffic (T1102).
* **Persistence:** Establishing scheduled tasks to maintain access (T1053.005).
* **Exfiltration/Tunneling:** Use of custom Python-based tools to create tunnels and exfiltrate data.
## Targeting
* **Sectors:** Critical Infrastructure, Government, Aviation, and Telecommunications.
* **Geography:** Primarily **Iraq**; secondary targets in the wider Middle East (UAE lures).
* **Victims:** Iraqi government entities and critical infrastructure providers.
## Tools & Infrastructure
* **Malware Families:**
* **Blinder Tunnel:** A custom malware written in Python that utilizes GitHub for C2 communication.
* **Custom HTA/VBScript:** Initial stagers for environment discovery.
* **Infrastructure:**
* **C2:** GitHub (Legitimate repositories used for command storage and data staging).
* **Lure URLs (Defanged):**
* `hxxps[:]//dubai-airports[.]net/recruitment/`
* `hxxps[:]//github[.]com/hr-dubai-airport/`
* **Payload Storage:** `hxxps[:]//raw[.]githubusercontent[.]com/[redacted]/main/update.ico` (masquerading as an icon but containing a script).
## Implications
* **Strategic Intent:** The campaign is likely focused on long-term espionage and strategic intelligence gathering related to Iraqi regional stability and infrastructure.
* **Threat Assessment:** The use of "Living off the Land" techniques (MSHTA, PowerShell) combined with legitimate cloud providers (GitHub) indicates a high level of operational maturity designed to bypass traditional perimeter defenses and signature-based detection.
## Mitigations
* **Application Whitelisting:** Restrict the execution of `mshta.exe`, `powershell.exe`, and `cmd.exe` to authorized users and processes only.
* **Network Monitoring:** Monitor for unusual outbound traffic to GitHub repositories, particularly those involving raw file downloads or non-standard communication patterns.
* **Email Security:** Implement robust attachment scanning to identify and block malicious LNK and HTA files.
* **Endpoint Detection (EDR):** Deploy EDR solutions to detect child processes of browsers or email clients initiating system scripts (e.g., `outlook.exe` -> `mshta.exe`).
* **User Training:** Conduct social engineering simulations focusing on specialized job recruitment lures targeting high-value employees.