WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Network switches with status lights in a dark server rackAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

This campaign expands on previous operations and incorporates a “Peaky Blinders” theme by naming infrastructure components after the British crime drama’s branding — even embedding its theme song into the malware (software written to damage a system or steal from it). Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure.

The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42 . Unit 42 tracks the activity as CL-STA-1178.

While other security vendors have discussed individual attacks linked to this activity, this is the first report that not only ties together these disparate attacks as related activity, but tracks the evolving 2026 activity and the Blinder Tunnel campaign as a whole. To blend in with legitimate cloud traffic, the campaign misused GitHub’s API (the interface one piece of software uses to talk to another) infrastructure for command-and-control (C2) communication. Palo Alto Networks customers are better protected from the Blinder Tunnel campaign through the following products and services: Advanced WildFire Advanced URL Filtering and Advanced DNS (the system that turns a domain name into an address) Security Cortex XDR and XSIAM Cortex AgentiX Agentic Assistant streamlined this investigation.

Sources & evidence