CL-STA-1178 (Blinder Tunnel): an Iranian-nexus recruitment lure delivers a Visual Studio project that runs code when it is opened, then hijacks the .NET AppDomainManager, disables ETW and takes tasking from GitHub
Unit 42: a coding-test Visual Studio project executes on open, then disables ETW and takes tasking from GitHub
Analysis
Unit 42 tracks an Iranian state-aligned cluster as CL-STA-1178 and names its March 2026 campaign against an individual in Iraqi critical infrastructure "Blinder Tunnel"; the infrastructure was staged from November 2025, and the same actor ran conflict-themed Google Drive credential phishing against an Israeli entity in May and June 2026 (Unit 42, 2026-10-06). A recruiter persona impersonating the Dubai Airports IT department sent a decoy career-portal installer and then a weaponised C# Visual Studio project as an at-home coding test (Unit 42, 2026-10-06). When a developer opens a project, Visual Studio runs a design-time build in the background, and the project file overrides one of the targets that step runs, so the payload executes at project load, before any compile; it copies binaries into a folder under the user profile and launches one of them (Unit 42, 2026-10-06).
The launched binary is a renamed, signed Microsoft Visual Studio hosting process. A configuration file beside it replaces the .NET application's default app-domain manager with a malicious one and sets the ETW enable flag to false, which Unit 42 says could impair detection, and the loader, ShelbyLoader V2, then arrives through DLL sideloading (Unit 42, 2026-10-06). The loader persists through a current-user startup registry value, authenticates to the GitHub API with a hard-coded personal access token for tasking, and falls back to encrypted routing data in comments on GitHub issues; a follow-on module hooks the PowerShell engine inside the hijacked process, so commands run without starting powershell.exe, and a second loader, Blackwood, runs the open-source Chisel tunnelling tool in memory to give a reverse SOCKS proxy into the victim's network (Unit 42, 2026-10-06). GitHub removed the malicious infrastructure Unit 42 identified, and Unit 42 is not aware of any breach of Dubai Airports (Unit 42, 2026-10-06).
Triage: developers legitimately build projects and call GitHub, so the discriminators are that execution starts at project open rather than at a build the developer chose to run, a DLL beside a renamed signed host binary that does not belong to it, and a configuration file that changes ETW or app-domain settings.
Cited evidence
We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets.
the attackers defined a custom XML target with this exact name in their malicious .csproj file, overriding the safe Microsoft default behavior.
Because Event Tracing for Windows (ETW) is critical for monitoring execution and detecting in-memory threats, this flag could impair detection capabilities.
This allowed the attacker's script to execute without spawning PowerShell.exe.
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.