Iranian Cyberespionage Campaign Breaches Iraqi Kurdistan Cloud

News related to:Dream · 2 min read

TEL AVIV, ISRAEL, October 11, 2026 /CourierPR/ -- Dream, a cybersecurity firm, has uncovered a sophisticated Iranian cyberespionage campaign that breached the cloud environment of the Kurdistan Region of Iraq's government and exfiltrated at least 1 GB of data. The campaign, which was active during August and September 2026 and remains ongoing, is part of the Iranian-linked Blinder Tunnel, or DarkBlinders, cluster.

The attackers employed a range of tactics, including counterfeit government webmail and cloud-drive services, credential-phishing pages, and a fake video-meeting application. One of the newly identified tools, StarkMeet, presented victims with a conventional installer and a convincing meeting interface while secretly installing malware capable of maintaining access even after the visible application was removed.

Dream’s research revealed that the attackers were highly selective in their targets. The malware first registered infected computers and collected information about each host. Operators could then review that information before deciding whether to activate a more powerful second-stage backdoor capable of executing PowerShell commands and transferring files. Approximately ten systems appeared in the initial check-in data available to researchers, while only two identified victims appeared in the second-stage tasking channel, indicating that the attackers screened potential targets before choosing which systems to exploit further.

The investigation gained unusual visibility after reverse-engineering the malware exposed credentials providing read-only access to attacker-controlled GitHub repositories operating under the PeakyBlindersTeam account. These repositories contained initial system check-ins, host information, and commands issued to selected compromised systems, allowing researchers to connect the threat actor command and control infrastructure itself and observed activity carried out by the operators.

Palo Alto Networks’ Unit 42 had previously documented some of the infrastructure and tactics used by the attackers, establishing a connection between the latest activity and earlier waves. The investigation also uncovered infrastructure designed to impersonate government and regional institutions, with recovered phishing pages mimicking the Kuwait Ministry of Foreign Affairs and the GCC Secretariat General. Other infrastructure used themes associated with the Kurdistan Regional Government and its Ministry of Electricity, though the Kuwait and GCC findings did not establish that these institutions were successfully compromised.

Dream connected the latest activity to four earlier waves documented by Elastic Security Labs, Unit 42, and Group-IB, establishing continuity across five waves of the campaign. Based on infrastructure, malware architecture, operator activity, and victimology, Dream assesses with high confidence that the latest activity is associated with an Iranian threat actor and belongs to the DarkBlinders or Blinder Tunnel cluster. Dream separately assesses with medium-to-high confidence that the broader activity cluster is linked to activity tracked as UNC5795 and UNC5187.

The findings underscore the ongoing threat posed by Iranian cyberespionage to critical infrastructure and government entities. The sophisticated tactics employed by the attackers highlight the need for robust cybersecurity measures to protect sensitive data and prevent unauthorized access.

Start filing today

One press release free every week. No card required.

Create a free account