malware
Blinder Tunnel Campaign Targets Iraqi Infrastructure
Medium
Summary
A state-aligned Iranian threat actor, operating under the campaign name ‘Blinder Tunnel,’ has been targeting Iraqi critical infrastructure since November 2025, and significantly escalated activity in March 2026. The attackers use a multi-stage attack chain involving exploiting legitimate Windows developer files, AppDomainManager hijacking, and DLL sideloading to deploy malware, ShelbyLoader V2, and execute malicious code. Palo Alto Networks customers are better protected through Cortex AgentiX Agentic Assistant.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
