Operation Blinder Tunnel targets Middle East critical infrastructure

Operation Blinder Tunnel targets Middle East critical infrastructure

Palo Alto Networks’ threat intelligence and incident response team, Unit 42, has identified previously unreported activity attributed to an Iranian state-aligned threat actor targeting critical infrastructure in the Middle East.

Palo Alto Networks’ threat intelligence and incident response team, Unit 42, has identified previously unreported activity attributed to an Iranian state-aligned threat actor.

Unit 42 is calling the activity ‘Operation Blinder Tunnel’ and has linked it to a separate credential-harvesting campaign targeting an Israeli entity, as well as related activity involving aviation and other critical infrastructure in the Middle East.

The activity used a fake recruitment process and coding challenge to target an individual in Iraq’s critical-infrastructure sector who was likely a software engineer.

Unit 42 state that the attackers impersonated the Dubai Airports IT Department and sent the target a Visual Studio project disguised as a coding assessment. Simply opening the project could trigger a multi-stage malware infection, allowing the attackers to deploy a remote-access tool and establish a tunnel into the victim environment.

The attackers also left behind an unusual clue: they used Peaky Blinders-themed infrastructure and embedded the show’s theme song in a public GitHub repository.

Metadata left in the audio file pointed to an Iranian music site and became one of several artefacts supporting Unit 42’s assessment that the activity aligns with an Iranian-nexus threat actor.

Browse our latest issue

Intelligent CISO

View Magazine Archive