news.mlab.sh
Back to the feed
malware

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Medium
Image: Palo Alto Unit 42
Summary

A state-aligned Iranian threat actor, operating under the campaign name ‘Blinder Tunnel,’ has been targeting Iraqi critical infrastructure since November 2025, and significantly escalated activity in March 2026. The attackers use a multi-stage attack chain involving exploiting legitimate Windows developer files, AppDomainManager hijacking, and DLL sideloading to deploy malware, ShelbyLoader V2, and execute malicious code. Palo Alto Networks customers are better protected through Cortex AgentiX Agentic Assistant.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.