AGP Picks
View all

Dream links Kurdistan cloud breach to Iranian cyberespionage

11 hours ago
By AI, Created 11:29 UTC, Oct 11, 2026, AGP -

Dream says an Iranian-linked campaign breached a government cloud environment in Iraq’s Kurdistan Region, stole at least 1 GB of data and also compromised a high-profile Israeli security-sector figure. The findings extend a previously documented intrusion wave and show attackers selectively escalating into only some infected systems.

Why it matters: - The breach hit a government cloud environment in the Kurdistan Region of Iraq and exposed at least 1 GB of data. - The same campaign also compromised a high-profile Israeli individual tied to the security sector. - Dream says the activity shows an active Iranian cyberespionage effort with post-compromise access, not just initial phishing.

What happened: - Dream released research on October 11, 2026, detailing an active wave of Iranian cyberespionage observed in August and September 2026. - The campaign is tied to the Blinder Tunnel, or DarkBlinders, cluster. - Dream says the operators breached the Kurdistan Region of Iraq government cloud environment and exfiltrated at least 1 GB of cloud data. - The same campaign compromised a high-profile Israeli individual associated with the security sector.

The details: - The attack used counterfeit government webmail and cloud-drive services, credential-phishing pages and a fake video-meeting app. - A newly identified tool called StarkMeet showed victims a normal installer and meeting interface while separately installing malware that preserved access after the visible app was removed. - The malware first registered infected computers and collected host information. - Operators then reviewed the data before deciding whether to deploy a second-stage backdoor. - The second-stage tool could execute PowerShell commands and transfer files. - About 10 systems appeared in the initial check-in data. - Only two identified victims appeared in the second-stage tasking channel. - Dream says that pattern shows the attackers screened targets before escalating. - Dream gained visibility after reverse-engineering malware that exposed credentials for read-only access to attacker-controlled GitHub repositories under the PeakyBlindersTeam account. - Those repositories included initial system check-ins, host information and commands issued to selected compromised systems. - Dream’s interaction with the infrastructure was read-only. - Dream says researchers did not change or delete repository content and did not issue commands to any compromised system. - The investigation found phishing pages that mimicked the Kuwait Ministry of Foreign Affairs and the GCC Secretariat General. - Other infrastructure used themes tied to the Kurdistan Regional Government and its Ministry of Electricity. - Dream says the Kuwait and GCC findings show impersonation infrastructure and do not prove those institutions were compromised. - Dream connected the latest activity to four earlier waves documented by Elastic Security Labs, Unit 42 and Group-IB. - That linkage establishes continuity across five waves of the campaign. - Dream assesses with high confidence that the latest activity is tied to an Iranian threat actor and belongs to the DarkBlinders or Blinder Tunnel cluster. - Dream separately assesses with medium-to-high confidence that the broader cluster overlaps with activity tracked as UNC5795 and UNC5187. - The investigation used Dream’s agentic Campaigner system. - Dream says the Pivoter agent helped structure threat intelligence and expand infrastructure relationships. - Dream says the Malware Agent supported static and dynamic analysis of the malicious software. - Dream researchers reviewed and validated the findings and analyzed the repositories and malware. - The full technical report includes indicators of compromise and detection guidance for phishing infrastructure, persistence mechanisms and command-and-control activity. - A full report is available here and the company’s website is here.

Between the lines: - The selective escalation suggests the operators were not blasting every victim with the same payload. - The read-only repository access gave researchers rare visibility into operator workflow and command handling. - The infrastructure overlap across multiple earlier waves points to a sustained campaign rather than a one-off intrusion.

What's next: - Organizations in the region and in adjacent sectors may use the report’s indicators of compromise to hunt for credential-phishing infrastructure, persistence and command-and-control activity. - The newly mapped infrastructure may help defenders connect future intrusions to the same cluster. - Dream’s findings may also sharpen attribution and victimology for the broader DarkBlinders set of operations.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Kuwait Politics Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Kuwait Politics Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.