October 8, 2026

DarkBlinders: Inside an Active Espionage Campaign

Dream Research Labs

Executive summary

Dream uncovered a new, active wave of cyberespionage targeting Israel and the Kurdistan Region of Iraq, conducted by DarkBlinders, the threat actor behind the Blinder Tunnel campaign previously documented by Unit 42. We observed the campaign between August and October 2026, and it remained active at the time of publication. Our investigation confirmed the compromise of a high-profile individual in Israel and identified additional compromises affecting a government cloud environment in the Kurdistan Region.

The current wave used government webmail, cloud-drive, and meeting-service lures. We also identified phishing infrastructure impersonating the Gulf Cooperation Council (GCC) Secretariat General and Kuwait's Ministry of Foreign Affairs, indicating broader targeting of Gulf governmental and diplomatic entities. GitHub repositories under the PeakyBlindersTeam account served as the malware's command-and-control infrastructure. The operator reviewed metadata from infected hosts before selectively activating a second-stage backdoor, enabling PowerShell command execution on chosen systems.

Our investigation established three key findings:

  • Direct visibility into attacker operations and confirmed impact. Reverse engineering the malware enabled read-only access to the actor's command-and-control repositories, revealing operator tasking against a government cloud environment in the Kurdistan Region of Iraq and a high-profile individual in Israel associated with the security sector. Confirmed post-compromise activity included credential theft and the exfiltration of at least 1 GB of data from the government cloud environment.
  • Connections across five campaign waves. Dream Security linked the current campaign to four earlier waves, each of which used a different GitHub repository for C2. These waves were documented by Elastic Security Labs, Unit 42, and Group-IB, establishing continuity across previously reported operations.
  • Attribution linking the broader activity cluster. We assess with medium-to-high confidence that the examined DarkBlinders activity belongs to the same operational cluster as UNC5795 and Dust Specter. Shared infrastructure, overlapping victimology, and supporting attribution research further suggest, with medium confidence, that this cluster and UNC5187 may represent related subclusters within APT34.

Dream's agentic Campaigner system

Dream's Sphere national cyberdefense solution supported the investigation, using its Campaigner functionality as an agentic pivoting system. The Pivoter agent converted reporting into structured intelligence and expanded infrastructure relationships, while the Malware Agent supported static and dynamic analysis of the loader and backdoor. Researchers reviewed the findings and performed the repository access and malware validation described in this report.

Technical campaign overview

The campaign combined credential phishing with malware delivery. Government and cloud-service lookalikes collected credentials or presented attacker-controlled file downloads. StarkMeet, a fake video-meeting application, provided a credible reason for a recipient to install an application while a separate RuntimeBroker branch established persistence and loaded the malware.

The post-installation design separated discovery from activation. RuntimeBroker.dll collected host metadata and registered the system through myLic. The operator could then decide whether to provide host-specific activation material. RuntimeBrokerApi.dll was decrypted only for selected hosts and loaded directly into memory, after which the second-stage backdoor used myCode to retrieve tasking and return data.

Key technical findings

  • RuntimeBroker.dll contained a GitHub token used to access the PeakyBlindersTeam myLic repository.
  • Historical Lic.txt content supplied key material required to decrypt RuntimeBrokerApi.dll.
  • RuntimeBrokerApi.dll contained a second token associated with the myCode tasking repository.
  • The repositories exposed approximately ten initial check-ins but only two identified victims in the second-stage tasking channel, supporting a selective activation assessment.
  • The first observed myLic host was a virtual machine with a Persian keyboard layout and may have been an operator test system.
  • A separate remote file management service branded TommyFiles extended the actor's Peaky Blinders naming theme.

Research workflow and repository access

The investigation moved from loader analysis to repository history, payload recovery, and operator tasking. The workflow below shows the evidence path. Tokens are intentionally redacted in the figure.

Figure 1. Research workflow from RuntimeBroker.dll analysis to recovered operator tasking.

Loader analysis and myLic

Analysis of RuntimeBroker.dll identified an embedded GitHub personal access token and repository paths under PeakyBlindersTeam. The token provided read access to myLic. The repository contained check-in records created by malware instances, including host identifiers and system metadata used by the operator to evaluate newly registered systems.

Approximately ten distinct hosts appeared in the available check-in data. The difference between these initial registrations and the smaller set visible in myCode indicates that a check-in did not automatically result in full second-stage activation.

Key recovery and second-stage decryption

Repository history was essential to payload recovery. A historical version of Lic.txt preserved key material that was no longer available in the current file state. We reproduced the loader's process by deriving the AES-256 key from the SHA-256 hash of Lic.txt and using the first 16 key bytes as the initialization vector. This recovered RuntimeBrokerApi.dll in plaintext for analysis.

The loader normally decrypts RuntimeBrokerApi.dll and loads it directly into memory. This reduces the chance that the decrypted backdoor will be collected from disk. No matching plaintext sample was identified on VirusTotal at the time of analysis, which made repository history and local reproduction necessary to examine the second stage.

Backdoor analysis and myCode

RuntimeBrokerApi.dll contained a second embedded GitHub token associated with myCode. The repository held commands issued to compromised systems. These records connected the capabilities implemented in the backdoor with tasking from the live operation and provided visibility that static analysis alone could not provide.

The combined repositories show the operational sequence: myLic receives the initial beacon and host metadata; the operator selects a host and supplies activation material; RuntimeBroker.dll decrypts and loads RuntimeBrokerApi.dll; and the backdoor uses myCode for tasking and result exchange.

Figure 2. Local copies of the PeakyBlindersTeam GitHub repositories examined during the investigation.

Read-only research safeguards

Our interaction with the GitHub infrastructure was strictly read-only and limited to retrieving existing repository contents and commit history. We did not create, modify, or delete repository content, and we did not issue commands to any malware instance.

Phishing and delivery

The actor used two delivery paths. Lookalike government, webmail, and cloud-drive pages supported credential theft and file delivery. StarkMeet used a fake meeting application to persuade recipients to install malware. The available evidence supports these delivery mechanisms, but the original message used to deliver StarkMeet.zip was not recovered.

Government webmail credential theft

The campaign recreated Outlook Web App (OWA) login pages on domains impersonating the Kuwaiti Ministry of Foreign Affairs and the GCC Secretariat General. The clearest recovered artifact was an HTML page that copied Microsoft OWA code and referenced official-looking assets from mail.mofa.gov.kw. The form collected usernames and passwords and submitted them to an attacker-controlled /owa/auth.owa endpoint.

Figure 3. Credential phishing page impersonating the Kuwait Ministry of Foreign Affairs Outlook login. Artifact SHA-256: 770646093df203013b190ef0b0baa9dd2f6834534970a57ac5dc4be9b22ad28e

The page did not contain an exploit or malware download. Its purpose was credential collection. A successful submission could expose email, contacts, shared files, and linked cloud services without producing an endpoint malware alert.

Cloud-drive delivery lures

The actor also reproduced the structure of Google Drive sharing links on attacker-controlled domains. Paths using /drive/file/d/<identifier>/view appeared on generic drive domains and on domains themed around the Kurdistan Regional Government and its Ministry of Electricity. The presentation gave recipients a familiar file-sharing workflow while keeping the download under attacker control.

Figure 4. Drive-style delivery page on moelcloud[.]online presenting Attachment.zip.

In the captured example, the page presented Attachment.zip, reported that the archive could not be previewed, and directed the recipient to download it. This design converts an expected preview failure for a ZIP archive into a prompt for user execution.

Malware delivery through StarkMeet

StarkMeet was presented as a video-meeting application. The installer displayed a conventional setup wizard for version 3.2 and opened a functional-looking meeting interface. The Join function returned a fixed failure rather than contacting a real meeting service, allowing the visible application to serve as a decoy while the RuntimeBroker components were installed separately.

Figure 5. StarkMeet installer and decoy meeting interface.

Malware execution and selective activation

The infection chain combines a meeting-client decoy, a signed .NET host, an AppDomainManager-based loader, and an encrypted second-stage backdoor. GitHub provides separate channels for host registration and operator tasking. This separation allows the operator to review infected systems before supplying the material required to activate the backdoor.

Figure 6. StarkMeet component and execution sequence.

Delivery and decoy application

Campaign infrastructure referenced StarkMeet.zip, although neither the archive nor the original delivery message was recovered. Phishing email or a meeting invitation remains a plausible but unconfirmed delivery route.

The analyzed installer is an unsigned Inno Setup package presented as StarkMeet version 3.2. It installs the visible application under %LOCALAPPDATA%\StarkMeet and the malicious components under %LOCALAPPDATA%\Microsoft\RuntimeBroker. These components operate independently, allowing the RuntimeBroker.exe branch to remain persistent after the visible application is removed.

StarkMeet.exe is a .NET Framework 4.8 meeting-client decoy featuring "Stark Industries" branding and Marvel-themed participants. Camera, microphone, and screen-sharing previews function locally, but clicking Join always produces the error "Stark Meet couldn't reach a meeting server." Analysis identified no networking, persistence, or payload deployment functionality in the decoy itself.

An embedded PDB path places the application under C:\Users\Admin\Desktop\Projects\PeakyBlinders\. The same development directory appears in the PDB path of PsProxy.dll, the PowerShell execution helper embedded in the second-stage backdoor.

Loader execution, persistence, and host registration

A legitimate, signed vshost.exe, renamed RuntimeBroker.exe, loads RuntimeBroker.dll. The loader exits unless the host executable resides at the expected path: %LOCALAPPDATA%\Microsoft\RuntimeBroker\RuntimeBroker.exe

Persistence is maintained through the MicrosoftRuntime value under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pointing to the same executable. The first persistence check occurs 121 seconds after startup and repeats hourly.

The loader derives a victim identifier from the first 16 lowercase hexadecimal characters of: SHA256("Peaky Blinders 2.1" + UserSID + MachineName + UserDomainName)

Using an embedded personal access token, it accesses the GitHub Contents API and writes a host report to PeakyBlindersTeam/myLic at {id}/{id}Inf.txt. The report contains the machine name, user and domain, logon server, time zone, interface language, installed keyboard layouts, local time, persistence status, and anti-analysis findings.

The environmental checks cover anti-analysis tests and virtual-machine artifacts, analysis-tool processes, hardware resources, timing anomalies, MAC address prefixes, usernames and hostnames, process counts, system-drive age, and the parent process. These checks produce [INFO] and [ALARM] entries in the report but do not stop execution. Their results provide the operator with information for deciding whether to activate the host.

Selective activation and payload decryption

The loader requests host-specific activation material from {id}/{id}Lic.txt in myLic. After Base64-decoding the retrieved content into a license string, it overwrites the repository file with a newline.

The license string supplies the material needed to decrypt the locally stored RuntimeBrokerApi.dll:

  • Algorithm: AES-256-CBC with PKCS7 padding.
  • Key: SHA-256 hash of the license string.
  • Initialization vector: The first 16 bytes of the derived key.

The plaintext .NET assembly is loaded directly into a new AppDomain, without writing the decrypted DLL to disk. Clearing the license file removes the material from its current contents, although previous versions may remain accessible through Git history.

This design separates initial registration from operational access. A host can report to myLic while the second-stage backdoor remains encrypted, pending delivery of the required activation material.

Backdoor communications and command execution

On startup, RuntimeBrokerApi.dll creates a mutex named Global\ followed by the full hexadecimal SHA-256 hash of "GSC" + id. It exits if the mutex already exists, preventing multiple instances for the same victim identifier.

The backdoor communicates with PeakyBlindersTeam/myCode using a separate embedded GitHub token. Its primary endpoint is api.github.com, with a Cloudflare Worker available as a fallback relay. Before accepting the relay, the malware checks that its /rate_limit response contains GitHub-shaped JSON and an X-GitHub-Request-Id header.

Tasking is retrieved from {id}/{id}.txt approximately every 63 seconds. If the command file is missing but the repository is accessible, the implant creates an empty file. After reading a command, it clears the file by replacing its contents with a newline.

Results are written beneath the same victim directory using filenames that combine inverted .NET ticks and a readable timestamp. The inverted value causes newer results to sort before older ones. Command and result text is Base64-encoded, without additional application-layer encryption.

PowerShell execution is provided by PsProxy.dll, embedded as Base64 within the backdoor and loaded through Assembly.Load(). Its PsProxy.PSExecutor.RunCommand method creates a System.Management.Automation runspace. Commands therefore execute within the existing process without spawning powershell.exe, limiting visibility from detections that rely on that child process.

Alongside PowerShell execution, the backdoor implements the following commands:

CommandFunctionDescription
/dlDownload a fileRetrieve a file from the victim's repository directory and write it to a local path.
/upUpload a fileUpload a local file to the victim's repository directory with a timestamped name.
/deDownload and extract a ZIPRetrieve a ZIP archive from the repository and extract it to a local directory.
/rateQuery API limitsReturn GitHub API rate-limit information.

Credential rotation through public GitHub comments

Both malware stages implement a mechanism for replacing their GitHub account, repository, and token settings. This routine runs hourly and can also be triggered by an HTTP 403 access failure, with failure-triggered attempts limited to once every 30 minutes.

The main channel depends on a GitHub token hardcoded in the binary. If GitHub revokes that token or takes down the repository, the implant is orphaned. A "magic comment" lets the operator hand every implant a new owner, repository, and token without touching the victim, by posting to one of the busiest public repositories on GitHub. The malware searches issues in the public Microsoft/vscode repository:

  • GET /search/issues?q=<yyyyMMdd>+repo:Microsoft/vscode+type:issue searches for issues matching today's date string.
  • For each result, it fetches the issue's comments_url and takes the text inside the first <!-- … --> block in each comment.
  • It removes the date string, CR/LF characters, and the comment markers from that text. The code expects the date to sit inside the hidden block.
  • It Base64-decodes and AES-CBC-decrypts the result five times in a row (PKCS7 padding), with key = MD5(yyyyMMdd + victimID) and IV = MD5(key).
  • It applies the result in memory only if all three of Owner=…, LicRepo=…, and LicToken=… are present. Otherwise, it keeps the current settings, logging "Magic comment not found — keeping existing credentials".

Obfuscation and binary metadata

Both RuntimeBroker.dll and RuntimeBrokerApi.dll are obfuscated with Obfuscar and carry Microsoft-themed version information, including version 10.0.26100.7019 and the description "Microsoft® Windows® Operating System."

Operator infrastructure and victim visibility

Peaky Blinders naming theme

The GitHub account name PeakyBlindersTeam made the theme explicit. The actor retained the operational repository names myLic and myCode while moving them under this account. We also identified remote file infrastructure branded TommyFiles. The name appears to reference Tommy Shelby, the central character in Peaky Blinders, and extends the same theme beyond GitHub.

Naming is not sufficient for attribution on its own. In this case, the shared theme accompanies the same malware workflow, repository naming, and operational role, making it useful for clustering infrastructure and guiding pivots.

TommyFiles remote file infrastructure

Figure 7. TommyFiles remote file management console associated with actor FTP infrastructure.

The recovered interface presented a username and password prompt for a remote file management console. Its role is consistent with operator-controlled staging or file management, although the screenshot alone does not establish which payloads or stolen data were stored behind the service.

Observed hosts and likely testing

The myLic repository contained check-in records for approximately ten distinct hosts. The first observed system was a virtual machine configured with a Persian keyboard layout. We assess that it may have been an operator test environment used to validate infrastructure or malware behavior before victim activation. This remains an analytical judgment because the available record does not identify the system owner.

Confirmed victim visibility

The myCode repository provided visibility into two victims that progressed beyond initial check-in. One was a government entity in the Kurdistan Region of Iraq whose affected environment was associated with cloud infrastructure. The second was a high-profile individual in Israel associated with the security sector.

The difference between approximately ten myLic registrations and two myCode victims is consistent with deliberate operator selection. Systems could beacon to myLic without receiving the key material required for RuntimeBrokerApi.dll, allowing the operator to reserve the full backdoor for hosts considered operationally relevant.

Figure 8. Analysis of the attacker's PowerShell commands used for data exfiltration from the Iraqi cloud environment.

Historical campaigns

During our investigation, we identified earlier DarkBlinders campaigns and GitHub infrastructure used during 2025, including the accounts johnshelllby, arturshellby, and GreenBeret0. We subsequently observed the actor's infrastructure evolve through peakyblinders-team and peakyblinders-tm, followed by the newest campaign using PeakyBlindersTeam. Our review of the ClickHouse public GitHub-event archive also identified a previously unreported account, PeakyBlindersTM, created on 26 August 2025. Minutes after its creation, this account created main branches for repositories named PeakyBlindersTeam.github.io and PeakyBlindersTM. Although its naming and timing make it a relevant investigative lead, no published reporting or additional technical evidence currently confirms its association with DarkBlinders.

Attribution and relationships between activity clusters

Dream Security assesses with medium-to-high confidence that the DarkBlinders activity examined in this report belongs to the same operational cluster as activity tracked as UNC5795 and Dust Specter. This assessment draws on extensive infrastructure associations and matching malware samples across the documented campaigns.

A further infrastructure connection links this combined cluster to UNC5187. Historical server fingerprints, overlapping victimology, and supporting attribution research lead us to assess with medium confidence that UNC5795 and UNC5187 may represent related subclusters within the broader APT34 group.

Indicators of an Iranian nexus

Infrastructure testing

During our analysis, passive DNS history showed that starkmeet[.]com used ParsVDS nameservers and resolved to 51.79.96[.]115, an address within OVH Hosting infrastructure in Canada. The use of ParsVDS provides limited contextual support for an Iranian nexus, although this infrastructure association alone does not establish the operator's location or identity.

Figure 9. Passive DNS history for starkmeet[.]com showing ParsVDS nameservers and the observed A record.

Operator environment

The earliest check-in visible in myLic came from a VM with a Persian keyboard layout. Its position as the earliest recorded check-in, together with the environment metadata, suggests that it may have been an operator test system. The Persian keyboard layout is consistent with an Iranian nexus, but does not independently establish attribution.

Together, these observations provide contextual support for the Iranian nexus assessed through the infrastructure and malware relationships detailed below.

Linking DarkBlinders to UNC5795

Correlating infrastructure and malware from successive DarkBlinders campaigns with Google Threat Intelligence (GTI) identified extensive associations with UNC5795. These span domains, related subdomains, hosting addresses, and delivery URLs across multiple waves. The infrastructure included domains themed around telecommunications providers, airports, meeting services, and network speed tests.

Malware sample mappings reinforce this relationship. The HTTPService.dll and HTTPApi.dll samples documented by Elastic Security Labs as SHELBYLOADER and SHELBYC2 (the earlier-wave counterparts of RuntimeBroker.dll and RuntimeBrokerApi.dll, respectively) are classified as HOTAIR and AEROSTAT and associated with UNC5795.

The infrastructure associations across successive campaigns, supported by these malware mappings, underpin our medium-to-high-confidence assessment that the examined DarkBlinders activity falls within UNC5795. Google's public reporting on UNC5795's use of HOTAIR and AEROSTAT against Middle Eastern targets provides additional corroboration.

Connecting Dust Specter to the same cluster

Applying the same correlation to Dust Specter revealed extensive infrastructure and malware associations with UNC5795. These included meeting-service and commercial-themed domains used for command and control, together with related URLs and hosting addresses.

The tooling provides a further connection. The RiroDiog.exe sample documented by Zscaler as GHOSTFORM is classified as TREEWORLD and associated with UNC5795. This exact sample match reinforces the infrastructure associations. TREEWORLD also appears alongside HOTAIR and AEROSTAT in Google's public description of UNC5795 operations, connecting the tooling observed across the DarkBlinders and Dust Specter campaigns.

DarkBlinders and Dust Specter therefore converge on UNC5795 through their respective infrastructure and malware associations. We assess with medium-to-high confidence that the examined campaigns belong to a common operational cluster. For the remainder of this section, UNC5795 refers to this combined body of activity.

Infrastructure linking UNC5795 and UNC5187

A pivot from the Dust Specter–associated domain meetingapp[.]site revealed an infrastructure connection to UNC5187. Passive DNS records showed that the domain resolved to 89.46.233[.]239 between 26 May and 2 June 2026.

The same address had previously served as command-and-control infrastructure for windowsObject.exe, an ENDDOT-family sample associated with UNC5187. The malware communicated with the address on TCP port 10443, linking the UNC5187-associated infection chain to the server later used by UNC5795-associated infrastructure.

Historical service observations strengthen this connection. A distinctive HTTP banner hash associated with UNC5187 was observed on the address between February 2025 and February 2026. Across the broader period, from February 2025 through our investigation, SSH was repeatedly observed on the uncommon TCP port 4781, with banner changes corresponding to version upgrades. Despite these changes, the server retained the same SSH host key across available observations, including during the period when meetingapp[.]site resolved to the address. This stable cryptographic fingerprint provides additional evidence of continuity of the SSH endpoint across the two clusters' use of the infrastructure.

Figure 10. Infrastructure timeline for 89.46.233[.]239, February 2025 to October 2026: service exposure, banner changes, and domain resolution.

The recurring HTTP fingerprint, persistent SSH configuration, and unchanged SSH host key support an assessment of continued operator control across the relevant periods. Together, they strengthen the connection between the earlier UNC5187 activity and the server's subsequent use by UNC5795-associated infrastructure. Although these observations do not establish uninterrupted control by a particular operator, they support infrastructure reuse under related administration.

Possible placement within APT34

The infrastructure connection to UNC5187 provides one line of support for placing the combined DarkBlinders/UNC5795/Dust Specter cluster within the broader APT34 group. Its focus on Iraqi government targets and use of government-themed social engineering are also consistent with previously documented APT34-associated operations, although these characteristics are not exclusive to that group.

Existing attribution research provides further corroboration. Recorded Future identifies overlap between Dust Specter and TAG-135, which it tracks as an APT34 subcluster, while Google/Mandiant describes UNC5187 as having moderate-confidence ties to APT34. These assessments support connections to APT34 from both sides of the infrastructure relationship identified in our investigation.

Considering the technical findings, victimology, and supporting research together, we assess with medium confidence that UNC5795 may represent a subcluster within APT34 and that UNC5187 may constitute another related subcluster. Their precise organizational placement remains unresolved.

Assessing the relationship between UNC5795 and UNC5187

The infrastructure sharing suggests an operational relationship between UNC5795 and UNC5187. A server used by UNC5187-associated malware later supported UNC5795 infrastructure, while its historical fingerprints and unusual SSH configuration indicate likely continuity of administration across the relevant periods.

Their overlapping focus on Iraqi government entities adds context to this technical connection and suggests a shared intelligence collection interest. Combined with their respective APT34 associations, these findings support a medium-confidence assessment that the two clusters are operationally related and may belong to the same broader group.

UNC5795 and UNC5187 could represent different portions of one team's activity, or distinct but closely connected APT34 subclusters sharing infrastructure or supporting resources. We retain the separate designations because the available evidence establishes a relationship more clearly than it establishes the organizational structure behind it.

Figure 11. Attribution relationships: the infrastructure and malware evidence connecting the activity clusters.

Indicators of compromise

This section consolidates the indicators from this investigation for detection and hunting. Certificates are excluded. Domains are reduced to the main registered domain, with subdomains retained only when they identify a distinct shared-service resource. URL entries are limited to credential pages, file-delivery paths, payload downloads, and operational backend endpoints. Domains, URLs, and IP addresses are defanged.

GitHub and Cloudflare are shared platforms. Match the exact account, repository, Worker hostname, and path shown below rather than blocking github.com, api.github.com, workers.dev, or Cloudflare services globally.

Domain indicators

DomainDescriptionTarget or role
gcc-sg[.]cloudGCC Secretariat General cloud and webmail lureGCC and Gulf diplomacy
gcc-sg[.]onlineGCC Secretariat General webmail lureGCC and Gulf diplomacy
mfakuwait[.]orgKuwait Foreign Affairs Outlook phishingKuwait
mofakuwait[.]onlineKuwait Foreign Affairs lookalikeKuwait
mfakuwait[.]onlineKuwait Foreign Affairs Outlook phishingKuwait
mfakuwait[.]websiteKuwait Foreign Affairs Outlook phishingKuwait
krgcloud[.]onlineKurdistan Regional Government cloud and file lureIraq and Kurdistan Region
moelcloud[.]onlineKRG Ministry of Electricity file lureIraq and Kurdistan Region
korektell[.]comKorek Telecom lookalikeIraq and Kurdistan Region
msonedrive[.]cloudMicrosoft OneDrive lookalikeGlobal cloud users
vision-cloud[.]onlineGeneric cloud and drive lureUnresolved
gsecurity[.]helpGoogle account security lureGlobal cloud users
secure-googe[.]helpMisspelled Google security lureGlobal cloud users
googedrive[.]onlineMisspelled Google Drive lureGlobal cloud users
cdn-gdrive[.]cloudGoogle Drive and CDN lureGlobal cloud users
cdndrive[.]onlineCloud drive delivery lureGlobal cloud users
drivegooge[.]onlineMisspelled Google Drive lureGlobal cloud users
drive-googe[.]onlineMisspelled Google Drive lureGlobal cloud users
drive-g[.]cloudGoogle Drive style file deliveryGlobal cloud users
drive-go[.]camGoogle Drive style lureGlobal cloud users
ukcentral[.]teamUnresolved UK cloud geography themeLow confidence UK theme
meetcloud[.]siteGeneric cloud meeting lureGlobal users
meetgooge[.]onlineMisspelled Google Meet lureGlobal users
googemeet[.]onlineMisspelled Google Meet lureGlobal users
accountmeetgooge[.]onlineGoogle Meet account lureGlobal users
meetgooge[.]camMisspelled Google Meet lureGlobal users
meet-goo[.]camGoogle Meet style lureGlobal users
meetlogin[.]onlineGeneric meeting login lureGlobal users
meetonline[.]camGeneric online meeting lureGlobal users
stark-meet[.]comStarkMeet decoy brand and payload deliveryCampaign infrastructure
stark-meet[.]onlineStarkMeet decoy brandCampaign infrastructure
stark-meet[.]websiteStarkMeet decoy brandCampaign infrastructure
starkmeet[.]comStarkMeet landing and download siteCampaign infrastructure
artcyberspacetraining[.]siteGeneric cyber training infrastructureUnresolved
optionbmitfilterport[.]siteOpaque campaign infrastructureUnresolved
artwavecollective[.]siteGeneric organization infrastructureUnresolved
astravioncapital[.]siteGeneric finance infrastructureUnresolved
lifeinmotionnow[.]siteGeneric lifestyle infrastructureUnresolved
g-prx.itugegape524.workers[.]devCloudflare Worker used as an operational proxyShared service exact host

URL indicators

FunctionURLDescription
Credential phishinghxxps://gcc-sg[.]cloud/owa/auth/logon.aspx?replaceCurrent=1&url=/owa/&reason=0GCC Outlook Web App credential page
Credential phishinghxxps://mfakuwait[.]org/owa/auth/logon.aspx?replaceCurrent=1&url=/owa/&reason=0Kuwait Foreign Affairs Outlook credential page
Credential phishinghxxp://mfakuwait[.]online/owa/auth/logon.aspx?replaceCurrent=1Kuwait Foreign Affairs Outlook credential page
Credential phishinghxxps://mfakuwait[.]website/owa/auth/logon.aspx?replaceCurrent=1&url=/owa/&reason=0Kuwait Foreign Affairs Outlook credential page
File deliveryhxxps://cdndrive[.]online/drive/file/d/1JpH3ySmJpvX6TyGnF7C-S8qYiaoxyC5O/viewGoogle Drive style file link
File deliveryhxxps://drive-g[.]cloud/drive/file/d/15EMLDq9hpNXyZdu7RIZokPWLSdDC0y_0/viewGoogle Drive style file link
File deliveryhxxps://krgcloud[.]online/drive/file/d/1JpH3ySmJpvX6TyGnF7C-S8qYiaoxyC5O/view?ref=3yh3q5KRG-themed Google Drive style file link
File deliveryhxxps://moelcloud[.]online/drive/file/d/1JpH3ySmJpvX6TyGnF7C-S8qYiaoxyC5O/view?ref=3yh3q5KRG Electricity-themed file link
Payload deliveryhxxps://stark-meet[.]com/wp-content/uploads/2025/08/StarkMeet.zipDirect StarkMeet archive download
Payload deliveryhxxps://starkmeet[.]com/downloadStarkMeet download page
Operational backendhxxps://api.github[.]com/repos/PeakyBlindersTeam/myLicCampaign repository API endpoint on a shared service
Operational backendhxxps://api.github[.]com/repos/PeakyBlindersTeam/myLic/contents/cd8c5ffad5278fa0/cd8c5ffad5278fa0Lic.txtHost activation file endpoint on a shared service
Operational backendhxxps://api.github[.]com/repos/PeakyBlindersTeam/myLic/contents/cd8c5ffad5278fa0/cd8c5ffad5278fa0Inf.txtHost information file endpoint on a shared service
Operational backendhxxps://g-prx.itugegape524.workers[.]dev/rate_limitCloudflare Worker proxy rate endpoint
Operational backendhxxps://g-prx.itugegape524.workers[.]dev/repos/PeakyBlindersTeam/myLic/contents/cd8c5ffad5278fa0/cd8c5ffad5278fa0Lic.txtProxied host activation file endpoint
Operational backendhxxps://g-prx.itugegape524.workers[.]dev/repos/PeakyBlindersTeam/myLic/contents/cd8c5ffad5278fa0/cd8c5ffad5278fa0Inf.txtProxied host information file endpoint
Operational backendhxxps://g-prx.itugegape524.workers[.]dev/search/issues?q=20260825+repo:Microsoft/vscode+type:issueProxied issue search used by the communications logic
Direct servicehxxp://194.62.249[.]114/8001Direct campaign service on TCP port 8001
Operational backendhxxps://api.github[.]com/repos/PeakyBlindersTeam/myCodeSecond-stage tasking repository API endpoint on a shared service

Hosting IP indicators

IP addressHosting countryCampaign roleObserved
194.62.249[.]19United KingdomHosts Google Drive and Meet lookalikes2026-07-08 to 2026-10-01
194.62.249[.]114United KingdomHosts Google and webmail lookalikes and a port 8001 service2026-08-05 to 2026-10-01
194.62.249[.]53United KingdomHosts Middle Eastern government and telecom lookalikes2026-09-15 to 2026-09-16
89.125.209[.]80NetherlandsHosts the starkmeet[.]com decoy brand2026-09-05 to 2026-09-30
78.17.71[.]148NetherlandsHosts the vision-cloud[.]online cluster2026-07-05 to 2026-07-08
77.223.215[.]140GermanyMulti-service host resolving campaign domains2026-01-29 to 2026-10-01

File and content hashes

TypeHashDescription
SHA-256052702d652286482863a70eaa37e4fc894f40c8b08dccf245ced46916e7f419fDubai Airport careers lure executable
SHA-25606d68dcb8088546cb40fb3d7e87d6a593cbdf4cc1e43017604faf786ad6dbd41Malicious .NET payload from the Dubai Airport lure package
SHA-2560702d54b03bf601019b6ad039f76ecc49b5b3e564119dfd60aebd742c8e90300Build artifact from the Dubai Airport lure package
SHA-2560c9869b4aa7dde55936ab8726c442368b722eb69b785ef5c8e24938a01fdee89.NET AppDomainManager loader configuration
SHA-25611d1d570b5db7639d56a40621045e96c33b3d1ec3ae49e63c2ff07b9865844d4StarkMeet installer variant
SHA-25613216e9942e15a48228005092f4e5ff8b7382d4ec73673f88c6d7b6c103cbce0Text file bundled with the Dubai Airport lure
SHA-2561421fc1d0c06bf410b16f2cc44d49988c30cd64edf4dd08dd23ac64b28b5c641Visual Studio workspace artifact from the lure archive
SHA-2561d1754948c42a85f4b613dfe3de8cfb100d334da956244e4b58f5ea9d6463fedVisual Studio index artifact from the lure archive
SHA-25622beddd7fd5d6df6104fc4987ca892b6772c2b832ad31731f71d4de2e9d32c2bXML configuration bundled with a malicious archive
SHA-25639da663f083fad0ad8dcaac90b0760d166e2aa911f90a3c311a8121badc16020Uninstaller shipped with the StarkMeet package
SHA-2563ab16d953c71738788ef2f39b62cf47284750e98aada273187954536e1ee1c83Shortcut that launches the hidden StarkMeet component
SHA-2563f1961c951c105f289e64a8933c7d1ee34d71f1964999c01e97f2d944dfdc33cKuwait Foreign Affairs HTML phishing document
SHA-2563f76edab26d08b1517a15bde8ca82e94d48b4cbedd005eb11c950cfd6d9a8982Packed StarkMeet executable variant
SHA-2563fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13Embedded in-process PowerShell helper
SHA-2563fde5576233852cb9fdc0d6c2c4956a8eaa0857c2bbd86c388d7b4e10f11b0e8Kuwait Foreign Affairs HTML credential page
SHA-256415eb0d0055bc113df2da361b35c4de65ff55d5cddea3b637660b3ad19848ebdHTML and JavaScript credential phishing page
MD5482c32947763a613199c43f7b4760f33Hash present in the source inventory without file context
SHA-25648e6a4196bff405b8b8ef80dcba599b93cb0428f3e587da90be6020e2337c83eHTML page supporting the StarkMeet decoy brand
SHA-25653f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402Malicious .NET loader masquerading as Runtime Broker
SHA-2566e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239Archive carrying the Dubai Airport careers lure
SHA-2566ec2c97eeddf741a2f8dcd7b4c720c7f5a3f7afe5205ca1cf1e62d9199333e4bBuild cache from the Dubai Airport lure project
SHA-256770646093df203013b190ef0b0baa9dd2f6834534970a57ac5dc4be9b22ad28eKuwait Foreign Affairs Outlook credential page
SHA-256824b36b9af74655a2c53b73959c144028b1f8ccc7c45ef17455d020b74cd0a51StarkMeet decoy meeting executable
SHA-25685c119297f42f09f9414e138b8f137a3e2dac1ee56fb6ae79c4c5044bc87bd80JSON configuration retrieved through the campaign API channel
SHA-25687bd8af14932f132bb3df9a6b8c17748c3e114432e217816a88ba35ec9a381f4StarkMeet executable variant
SHA-2568875a41ead3b17eb8538466bfecb211a52d7ee56fa6e496b4407bdb0caa51dc5Legitimate signed host repurposed by the loader
SHA-2568c68119ebef2ec4be1d57f867ecc1e3606f819bd6278d35a95c6d9b789ac0bfdStarkMeet delivery archive
SHA-2569ceb74f9ca2b0e9e1f0e579bfbb5d3d376667165eff9b8cda616b1c4a74236b9StarkMeet installer variant
SHA-2569d4b61dae9e00940305c6ad7d862713025c07f27ecb5f89e59bcbd3fbcf17965Visual Studio solution from the Dubai Airport lure
SHA-2569d84672c95bfa4f2a3756053d21fd3b72508f51c7856837bd489f5edf283be10Second Visual Studio workspace artifact from the lure archive
SHA-256aa7d4bf74edacba06da7e9d414c0649599fb0e7b118f7c3ddcec09eb3f720c82Alternate malicious RuntimeBroker loader
SHA-256c9178fef804f2d6a525c1af0a8ba49a5ec692bfaabd6043e5f0094fe93a31e82RuntimeBrokerApi.dll
SHA-256aae2a7860f2e46019c38c1e7a50bc3b8f8104577acf750221c2cf23e6b376328StarkMeet installer variant
SHA-256ac91ba73040ed42fb4eda1459bb8098e2f80970f2028da80c4e2f01e281cc223Shortcut that launches a hidden executable
SHA-256b24a0c29134800dad72021e22d5ead99fa941722526807f29c131f6fbffa5fe2JavaScript used by the StarkMeet landing site
SHA-256c039da6d430f78fc2a405c8ae945d2114518a63d73857145bb244ab651e41f84Second-stage StarkMeet executable variant
SHA-256d8a4d54808c4705f472222c8a6ac5fd0622eb9bda7a2f07e12d712ea8b495d8eAlternate shortcut launching the hidden component
SHA-256dbd31b5d891d789e5cebbf0744a57b17c2f9a4fe50b79f64956e40dbb5fcaa9eOutlook Web App credential phishing page
SHA-256e325ba0f93dfdeeb8c35e159c54f9d4e796905056506f6d627f4d66f15fb9988GCC Secretariat Outlook credential page
SHA-256f2c54434e2eecca203c2114c0651e5d7a90fc2681117240686d084f016f9e2b6Alternate shortcut launching the hidden component
SHA-256f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9Visual Studio project from the Dubai Airport lure

Scope note: Hosting geography describes infrastructure location and should not be treated as victim geography. Indicator descriptions summarize the observed campaign role.

Get Dream's research and briefings first

Thanks, you're in.
Oops! Something went wrong while submitting the form.

Fill out the form to get in touch with our Expert Team.

Thank you!
Your submission has been received!
Oops! Something went wrong while submitting the form.