CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

CL-STA-1178

actor · actor:cl-sta-1178 single-source

Unit 42 designation for an Iranian state-aligned cluster behind the Blinder Tunnel campaign (March 2026, an individual in Iraqi critical infrastructure), with Peaky-Blinders-themed infrastructure that Unit 42 links to the activity Elastic documented as The Shelby Strategy; Unit 42 attributes it to Iranian state-aligned attackers with high confidence and reports only low-confidence overlaps with established Iranian groups (Unit 42, 2026-10-06).

Coverage
1
first 2026-10-07 → last 2026-10-07
Latest activity
2026-10-07
Unit 42: a coding-test Visual Studio project executes on open, then disables ETW and takes tasking from GitHub
Peak priority
notable
1 notable
Targets
aviation
sectors: aviation, telco, technology · regions: middle-east
Sources cited
1
1 hosts

Defender insights

What each entry about CL-STA-1178 tells a defender to do, newest first.

2026-10-07NOTABLEUnit 42: a coding-test Visual Studio project executes on open, then disables ETW and takes tasking from GitHub

Exposure · triage · detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

overlaps with

attributed activity

Story timeline

  1. 2026-10-07CL-STA-1178 (Blinder Tunnel): an Iranian-nexus recruitment lure delivers a Visual Studio project that runs code when it is opened, then hijacks the .NET AppDomainManager, disables ETW and takes tasking from GitHub
    active-threatsUnit 42: a coding-test Visual Studio project executes on open, then disables ETW and takes tasking from GitHub
ATT&CK techniques (12 across 6 tactics)

12 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ExecutionCommand and Scripting Interpreter: PowerShell · Trusted Developer Utilities Proxy Execution: MSBuild · User Execution: Malicious File · Hijack Execution Flow: DLL · Hijack Execution Flow: AppDomainManager
  • PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • StealthObfuscated Files or Information · Masquerading: Match Legitimate Resource Name or Location · Trusted Developer Utilities Proxy Execution: MSBuild · Hijack Execution Flow: DLL · Hijack Execution Flow: AppDomainManager
  • Defense ImpairmentDisable or Modify Tools
  • Command and ControlWeb Service: Dead Drop Resolver · Web Service: Bidirectional Communication · Protocol Tunneling

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1127.001Trusted Developer Utilities Proxy Execution: MSBuild×1

Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1574.014Hijack Execution Flow: AppDomainManager×1

Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

Persistence TA0003

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

Privilege Escalation TA0004

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1127.001Trusted Developer Utilities Proxy Execution: MSBuild×1

Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1574.014Hijack Execution Flow: AppDomainManager×1

Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

Command and Control TA0011

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1102.002Web Service: Bidirectional Communication×1

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗

Entries about CL-STA-1178 (1)

2026-10-07 · view entry permalink →

NOTABLENATOB2

CL-STA-1178 (Blinder Tunnel): an Iranian-nexus recruitment lure delivers a Visual Studio project that runs code when it is opened, then hijacks the .NET AppDomainManager, disables ETW and takes tasking from GitHub

Unit 42 tracks an Iranian state-aligned cluster as CL-STA-1178 and names its March 2026 campaign against an individual in Iraqi critical infrastructure "Blinder Tunnel"; the infrastructure was staged from November 2025, and the same actor ran conflict-themed Google Drive credential phishing against an Israeli entity in May and June 2026 (Unit 42, 2026-10-06). A recruiter persona impersonating the Dubai Airports IT department sent a decoy career-portal installer and then a weaponised C# Visual Studio project as an at-home coding test (Unit 42, 2026-10-06). When a developer opens a project, Visual Studio runs a design-time build in the background, and the project file overrides one of the targets that step runs, so the payload executes at project load, before any compile; it copies binaries into a folder under the user profile and launches one of them (Unit 42, 2026-10-06).

The launched binary is a renamed, signed Microsoft Visual Studio hosting process. A configuration file beside it replaces the .NET application's default app-domain manager with a malicious one and sets the ETW enable flag to false, which Unit 42 says could impair detection, and the loader, ShelbyLoader V2, then arrives through DLL sideloading (Unit 42, 2026-10-06). The loader persists through a current-user startup registry value, authenticates to the GitHub API with a hard-coded personal access token for tasking, and falls back to encrypted routing data in comments on GitHub issues; a follow-on module hooks the PowerShell engine inside the hijacked process, so commands run without starting powershell.exe, and a second loader, Blackwood, runs the open-source Chisel tunnelling tool in memory to give a reverse SOCKS proxy into the victim's network (Unit 42, 2026-10-06). GitHub removed the malicious infrastructure Unit 42 identified, and Unit 42 is not aware of any breach of Dubai Airports (Unit 42, 2026-10-06).

Triage: developers legitimately build projects and call GitHub, so the discriminators are that execution starts at project open rather than at a build the developer chose to run, a DLL beside a renamed signed host binary that does not belong to it, and a configuration file that changes ETW or app-domain settings.

We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets.

the attackers defined a custom XML target with this exact name in their malicious .csproj file, overriding the safe Microsoft default behavior.

Because Event Tracing for Windows (ETW) is critical for monitoring execution and detecting in-memory threats, this flag could impair detection capabilities.

This allowed the attacker's script to execute without spawning PowerShell.exe.

Palo Alto Networks Unit 42 2026-10-06
threat07 Oct 04:47Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • unit42.paloaltonetworks.com1 (100%)