A fake recruitment process can become an entry point into a developer’s environment. In a report published on 6 October 2026, Unit 42 described a campaign called Blinder Tunnel that targeted someone working in Iraq’s critical-infrastructure sector. The lure impersonated Dubai Airports and delivered a Visual Studio project framed as a coding exercise.
A recruitment journey designed to build trust
Researchers say the infrastructure had been prepared since November 2025 and was activated in March 2026. The first contact presented an offline recruitment portal posing as Dubai Airports IT. The potential victim was then asked to complete a technical assessment at home.
Unit 42 tracks the activity as CL-STA-1178 and assesses with high confidence that it is linked to an Iranian-nexus actor. This is the research team’s assessment, not an attribution published by an Iraqi authority. Researchers say they found no evidence that Dubai Airports systems were compromised.
The Visual Studio file as a trigger
The candidate received an archive containing a C# project presented as a coding test. According to Unit 42, the .csproj file changed a target Visual Studio can evaluate in the background. Opening the project could therefore run code before the recipient knowingly compiled or launched the application.
The observed chain included ShelbyLoader V2 and remote-access and network-tunnelling capabilities. The attackers used GitHub’s API to communicate with the compromised infrastructure. These details describe the sample that was analysed; they do not establish that every fake test or victim received the same payload.
Why developers are at risk
Software projects are not passive documents. Project formats, build scripts, dependencies, and development tools can execute tasks with the user’s permissions. A recruitment assignment looks plausible precisely because the recipient expects to open and inspect code.
The risk also depends on what the workstation can access: repositories, API tokens, VPN connections, or environment secrets. A poisoned project may aim beyond the test computer and reach work resources available in the developer’s session.
Checks before opening a coding test
Verify the recruiter through a channel found independently on the employer’s website. Check that the domain, contact address, and process match a real opening. An impersonated company is not necessarily responsible for the message.
Do not open unknown projects on your daily workstation. If an exercise must be analysed, use a disposable virtual machine or isolated environment without access to repositories, secrets, VPN, or personal accounts. Alert your security team before running anything suspicious; a local antivirus is not a guarantee.
The Soclyde connection
Soclyde does not detect malicious Visual Studio projects or protect compromised workstations. Its encrypted local-first vault helps reduce password reuse and organise team access. API tokens and keys should stay out of untrusted projects and be revoked in their source service if exposed.
The takeaway
Blinder Tunnel turns a developer application into an execution vector: according to Unit 42, opening a poisoned Visual Studio project could start the malicious chain. Verify recruiters, isolate external coding tests, and keep work secrets away from test environments. To organise small-team access, read our SMB password policy guide.

