Iranian Cyber Campaign Breaches Government Cloud and Exfiltrates Sensitive Data
Erbil, Sunday, 11 October 2026.
An active Iranian cyberespionage campaign exfiltrated government data from Iraqi Kurdistan and targeted Israeli security personnel, highlighting growing Middle Eastern digital threats to regional stability.
Technical Execution and Data Exfiltration
Security researchers have confirmed that an active Iranian cyberespionage campaign successfully breached the Kurdistan Region of Iraq government cloud infrastructure during August and September 2026 [1][2]. The threat actors utilized a malicious application named “StarkMeet,” which masqueraded as a legitimate video-meeting interface to install persistent malware on victim systems [1]. This operation resulted in the exfiltration of at least 1 GB of sensitive official data from the compromised government cloud environment [1][2]. The campaign employed a selective, two-stage exploitation process where initial check-in data was recorded for approximately 10 systems, but only two were escalated to a second-stage backdoor capable of PowerShell command execution and file transfer [1].
Target Profile and Regional Implications
In addition to the government breach, the operators compromised a high-profile Israeli national affiliated with the security sector, highlighting escalating Middle Eastern cyber risks [1][2]. Infrastructure identified during the investigation included phishing pages mimicking the Kuwait Ministry of Foreign Affairs, the GCC Secretariat General, and the Kurdistan Regional Government’s Ministry of Electricity [1]. These actions indicate that the conflict in the Gulf is increasingly playing out through stolen credentials, compromised systems, and intelligence gathering rather than solely through kinetic means [2][3]. The combination of credential theft with malware allows operators to review infected systems before selecting which to pursue for deeper access [2].
Campaign Continuity and Attribution
Dream security researchers identified this activity as the fifth wave of a campaign dubbed “DarkBlinders” or “Blinder Tunnel,” establishing continuity with previous waves documented by Elastic Security Labs, Unit 42, and Group-IB [1]. The firm assesses with medium-to-high confidence that the cluster is connected to threat actors tracked as UNC5795 and UNC5187, though attribution in cyberspace often carries inherent uncertainties regarding state sponsorship [alert! ‘attribution confidence is medium-to-high rather than definitive’][1]. Findings from this investigation extend the timeline beyond activity recently documented by Palo Alto Networks’ Unit 42, confirming successful intrusions and post-compromise activity [1]. The research utilized the company’s “Campaigner” system, specifically the “Pivoter” agent for infrastructure relationship mapping and a “Malware Agent” for static and dynamic analysis [1].
Operational Status and Risk Assessment
The campaign remains active at the time of publication, posing ongoing operational threats to regional government systems and cross-border corporate digital assets [2]. Researchers confirmed the campaign’s focus on credential harvesting and persistence, noting that their own investigation involved read-only access to compromised systems without modifying content or issuing commands [1]. This persistence underscores the need for heightened vigilance among entities associated with regional institutions, as the actors continue to refine their methods for data exfiltration and system compromise [2][3]. The findings sit alongside recent research into another campaign by the same actor, adding a new chapter to the picture of its activity across the region [2].