Iran‑linked Hackers Masquerade as Dubai Airports Recruiters to Deploy ShelbyLoader V2 Malware
Security researchers have uncovered a new social‑engineering campaign in which a threat group linked to the Iranian state pretended to be recruiters for Dubai Airports. The impostors sent fake coding assessments to software engineers, using the assignments as a vector to install a malicious loader known as ShelbyLoader V2.
The operation hinged on a multi‑stage execution chain that leveraged legitimate Microsoft development tools and repositories hosted on GitHub. By embedding malicious payloads within what appeared to be routine development artifacts, the attackers were able to bypass many traditional security controls that trust signed Microsoft binaries and popular open‑source platforms.
According to the analysis, the fake recruitment outreach was carefully crafted to target engineers with experience in the aviation sector. Recipients received an email that referenced Dubai Airports and invited them to complete a technical test. The test was delivered as a zip file containing a Visual Studio solution; when opened, the solution invoked a PowerShell script that fetched the ShelbyLoader V2 binary from a remote server, executed it in memory, and then established a foothold on the victim’s workstation.
ShelbyLoader V2 is a modular loader that can download additional payloads, exfiltrate data, and maintain persistence. Its use of trusted development tools makes detection difficult, as the malicious code runs under the same security context as legitimate build processes. Researchers note that the technique reflects a broader trend among state‑aligned actors to blend malicious activity with everyday developer workflows, increasing the likelihood of successful compromise.
The campaign highlights the growing risk of supply‑chain‑adjacent attacks that do not target the supply chain directly but instead exploit the tools developers rely on. Organizations are advised to scrutinize unsolicited recruitment communications, verify the authenticity of any coding assessments, and enforce strict controls on the execution of external scripts within development environments. Enhanced monitoring of PowerShell activity, code‑signing verification, and network traffic to unknown endpoints can help mitigate similar threats in the future.
While the full extent of the compromise remains under investigation, the incident underscores the importance of security awareness training for technical staff. As threat actors continue to weaponize trusted platforms, a combination of technical safeguards and user vigilance will be essential to protect both corporate networks and the intellectual property of software engineers.
Comments (0)
Be the first to comment.
Join the discussion