Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2

An Iranian state-aligned threat actor impersonated Dubai Airports recruiters to deliver weaponized coding assessments to software engineers. The operation deployed ShelbyLoader V2 through a stealthy execution chain that abused legitimate Microsoft development tools and GitHub infrastructure. Tracked as CL-STA-1178, the activity includes “Blinder Tunnel,” a campaign targeting Iraqi critical infrastructure beginning in March 2026. The […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: