accessibility-icon
share-icon

VIDEO

Photo: Dubai Airport

Iran-Linked Hackers Exposed in Major Cyberattack Operation

Marni Harow

By: Marni Harow

Editor: Marni Harow

09:45

Palo Alto Networks’ Unit 42 exposes an extensive Iranian state-aligned cyber operation that impersonated Dubai Airports’ IT department to infiltrate high-value targets across Israel, Iraq and the UAE — as scrutiny of Gulf aviation security heightens following the Flydubai terrorist attack.


A sophisticated Iranian state-aligned cyber operation targeting critical infrastructure across the Middle East has been exposed by Unit 42, the threat-intelligence, incident-response and cybersecurity arm of Palo Alto Networks. The extensive operation saw Iran-linked hackers pose as members of the Dubai Airports IT department and send carefully disguised, malicious coding challenges to high-value targets — ultimately attempting to establish covert access to their computer systems.

maximize-image
images-count8+
Dubai Airport Terminal | Photo: Shutterstock

Unit 42 brings together threat researchers, incident responders and security consultants to investigate major cyberattacks and identify the groups behind them. Palo Alto Networks says the team includes more than 200 threat researchers and analyzes roughly 30 million malware samples each day. The newly exposed operation, dubbed “Blinder Tunnel,” has been linked to targeted cyber activity against strategically valuable telecommunications, aviation and other critical entities across Israel, Iraq and the United Arab Emirates.

maximize-image
images-count8+
Ben Gurion Airport | Photo: Avshalom Shoshani, Flash 90

According to Unit 42, the hackers disguised themselves as Dubai Airports IT personnel and approached targets with what appeared to be legitimate coding challenges. The files were instead weaponized, launching a carefully constructed, multi-stage infection process designed to evade detection and establish covert access to the victim’s computer.

maximize-image
images-count8+
Dubai airport security | Photo: Dubai Airport

The researchers discovered that the group had been laying the groundwork for the operation months before the attacks began. Its infrastructure was staged and tested as early as November 2025 before remaining dormant until March 2026, when the attackers initiated targeting against an individual working in Iraq’s critical infrastructure sector amid heightened regional tensions.

maximize-image
images-count8+
Dubai Airport overview | Photo: Wikipedia\Umair Shaikh

The campaign also carried an unusual calling card: the attackers repeatedly referenced the British crime drama Peaky Blinders, naming parts of their infrastructure after the series and even embedding its theme song into the malicious payload. And there are some clues the hackers accidentally left behind. One of their command servers was on an Iranian ISP; metadata embedded in the Peaky Blinders theme-song MP3 they uploaded pointed to an Iranian music-download site; and reused infrastructure connected the operation to a separate attack targeting an Israeli entity in May–June. Those mistakes contributed to Unit 42’s high-confidence assessment that the operation was Iranian-linked. Behind the pop-culture references, however, was a sophisticated three-stage infection chain.

maximize-image
images-count8+
The attacker’s file, with the “Peaky Blinders” theme song | Image: Palo Alto

The hackers first weaponized a native .csproj file, a Microsoft developer file ordinarily used to build software projects. That triggered additional techniques known as AppDomainManager hijacking and DLL sideloading, allowing the attackers to evade detection and ultimately install a custom Remote Access Trojan, or RAT. Once installed, a RAT can provide an attacker with covert remote access to an infected system. In this case, Unit 42 said the custom malware used GitHub as its command-and-control server, allowing the hackers to communicate with the compromised machine through a legitimate and widely used online platform.

maximize-image
images-count8+
Overview of the Blinder Tunnel campaign | Image: Palo Alto

Most significantly, Unit 42 assessed with high confidence that the activity is linked to an Iranian-nexus threat actor. While other cybersecurity companies had previously tracked individual campaigns associated with the same cluster of activity, the investigation marks the first public attribution of the group to Iran, exposing the broader connection between previously observed cyber operations. The scope of the operation is particularly significant. Rather than conducting indiscriminate cyberattacks, the hackers focused on strategically valuable sectors across the Middle East, including aviation, telecommunications and other critical infrastructure in Israel, Iraq and the UAE.

maximize-image
images-count8+
Iran hacker | Photo: Nati Shohat, Flash90

The exposure comes amid heightened scrutiny of aviation security in the Gulf following the attempted terrorist attack aboard a Flydubai flight to Israel. The co-pilot, identified by multiple sources as Omani national Hamam al-Hammami, attacked the captain with an emergency crash axe and attempted to seize control of the aircraft, according to UAE prosecutors, who officially classified the incident as a “terrorist attack”, with possible links to Iran as well. Israeli officials familiar with the investigation have since said al-Hammami allegedly planned the attack before being hired by Flydubai and deliberately sought work with an airline flying to Tel Aviv — raising serious questions over how he was able to pass security screening and enter the cockpit of an Israel-bound passenger jet.

maximize-image
images-count8+
FlyDubai airplane | Photo: Shutterstock

There is no indication that the Flydubai terrorist attack was connected to Operation Blinder Tunnel. However, the two cases highlight separate vulnerabilities surrounding an aviation sector responsible for both critical infrastructure and the safety of millions of passengers, as well as evidence linking back to Iran.

The hackers themselves have not been publicly identified or apprehended. However, researchers were able to disrupt part of their operation, with GitHub taking down infrastructure used by the group to communicate with infected systems. The attackers also left behind a trail of digital clues that helped Unit 42 trace the operation back to an Iranian state-aligned threat actor.

maximize-image
images-count8+
Airport cybersecurity | Photo: Dubai Airport

The researchers warned that Operation Blinder Tunnel demonstrates how state-aligned hackers can exploit trusted professional identities, developer tools and legitimate technology platforms to penetrate sensitive organizations while attempting to conceal their presence. Unit 42 urged organizations to strengthen security around developer environments, monitor unusual traffic involving cloud platforms and remain particularly alert to highly tailored recruitment, coding and other industry-specific social-engineering approaches.