AGP Picks
View all

Dream Finds Iranian Cyberespionage Campaign Behind Kurdistan Government Cloud Breach

Attackers stole at least 1 GB of gov. data from Kurdistan Region of Iraq and compromised a high-profile Israeli individual associated with the security sector

TEL AVIV, ISRAEL, October 11, 2026 /EINPresswire.com/ -- Dream today released new research uncovering an active wave of Iranian cyberespionage that breached a government cloud environment in the Kurdistan Region of Iraq and exfiltrated at least 1 GB of cloud environment data. The same campaign also compromised a high-profile Israeli individual associated with the security sector.

The operation, observed during August and September 2026 and still active during Dream’s investigation, is part of the Iranian-linked Blinder Tunnel, or DarkBlinders, campaign. Dream’s findings confirm successful intrusions and post-compromise activity, extending the timeline beyond activity recently documented by Palo Alto Networks’ Unit 42.

The campaign used counterfeit government webmail and cloud-drive services, credential-phishing pages and a fake video-meeting application to gain access to targets. One of the newly identified tools, StarkMeet, presented victims with a conventional installer and convincing meeting interface while separately installing malware capable of maintaining access even after the visible application was removed.

Dream researchers also uncovered evidence that the attackers were highly selective about which compromised systems they pursued. The malware first registered infected computers and collected information about each host. Operators could then review that information before deciding whether to activate a more powerful second-stage backdoor capable of executing PowerShell commands and transferring files.

Approximately ten systems appeared in the initial check-in data available to researchers, while only two identified victims appeared in the second-stage tasking channel — indicating that the attackers screened potential targets before choosing which systems to exploit further.

Dream gained unusual visibility into the operation after reverse-engineering the malware exposed credentials providing read-only access to attacker-controlled GitHub repositories operating under the PeakyBlindersTeam account. The repositories contained initial system check-ins, host information and commands issued to selected compromised systems, allowing researchers to connect the threat actor command and control infrastructure itself and observed activity carried out by the operators.

Dream’s interaction with the infrastructure was strictly read-only. Researchers did not modify or delete repository content and did not issue commands to any compromised system.

The investigation also uncovered infrastructure designed to impersonate government and regional institutions. Recovered phishing pages mimicked the Kuwait Ministry of Foreign Affairs and the GCC Secretariat General, while other infrastructure used themes associated with the Kurdistan Regional Government and its Ministry of Electricity. The Kuwait and GCC findings demonstrate impersonation and targeting infrastructure and do not establish that either institution was successfully compromised.
Dream connected the latest activity to four earlier waves documented by Elastic Security Labs, Unit 42 and Group-IB, establishing continuity across five waves of the campaign.

Based on infrastructure, malware architecture, operator activity and victimology, Dream assesses with high confidence that the latest activity is associated with an Iranian threat actor and belongs to the DarkBlinders or Blinder Tunnel cluster. Dream separately assesses with medium-to-high confidence that the broader activity cluster is linked to activity tracked as UNC5795 and UNC5187.

The investigation was supported by Dream’s agentic Campaigner system. Its Pivoter agent helped structure existing threat intelligence and expand infrastructure relationships, while Dream’s Malware Agent supported static and dynamic analysis of the malicious software. Dream researchers reviewed and validated the findings and conducted the repository and malware analysis described in the report.

The full technical report includes indicators of compromise and guidance for organizations seeking to detect the campaign’s credential-phishing infrastructure, malicious persistence mechanisms and command-and-control activity.

Read the full report here.

About Dream
Dream develops sovereign AI and cybersecurity technologies for governments and critical infrastructure. Built for secure, mission-critical environments, Dream combines specialized AI systems with cybersecurity expertise to help governments understand, investigate and defend against sophisticated threats while maintaining control of their data and infrastructure.

Read more: www.dreamgroup.com
Media contact: media@dreamgroup.com

Raoul Wootliff
N10S
+972 546921720

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Today in Business

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.