An active Iranian cyberespionage operation has been caught red-handed breaking into a government cloud system in Iraq’s Kurdistan Region and swiping at least 1 GB of sensitive data, according to new research from cybersecurity firm Dream. The campaign didn’t stop there — it also hit a prominent Israeli individual tied to the security sector, making this a cross-border threat that demands attention.
TEL AVIV, ISRAEL, October 11, 2026 /EINPresswire.com/ — Security firm Dream has published findings that pull back the curtain on a live Iranian cyberespionage push that infiltrated a government cloud environment in the Kurdistan Region of Iraq, walking away with at least 1 GB of data from that cloud infrastructure. The same operation went on to compromise a well-known Israeli individual linked to the security field.
The activity, which Dream tracked through August and September 2026 and which remained live during the investigation, ties into the Iranian-connected Blinder Tunnel, also called DarkBlinders, campaign. Dream’s findings document confirmed breaches and actions taken after the initial compromise, pushing the known timeline beyond what Palo Alto Networks’ Unit 42 had previously reported.
Also worth a look: WebtrixPro centralizes Project Works estimating to stop silent profit leaks and Alvacomm takes on retail dependence with DropSync 360 for growers.
To pull off the intrusions, the attackers leaned on forged government webmail portals, cloud-drive lookalikes, credential-harvesting pages, and a phony video-conferencing app. One freshly uncovered tool, StarkMeet, showed victims a standard installer and a convincing meeting interface while quietly deploying malware that could keep a foothold even after the visible program was uninstalled.
Dream’s researchers also saw signs that the attackers were picky about which compromised machines they went after. The malware first registered infected devices and pulled basic host details. Operators could then eyeball that intel and decide whether to flip on a more potent second-stage backdoor, one that could run PowerShell commands and shuttle files around.
Roughly ten machines showed up in the initial check-in data the researchers could see, but only two confirmed victims appeared in the second-stage tasking channel — a clear sign the attackers vetted their targets before escalating against specific systems.
Dream got an unusually close look at the operation by reverse-engineering the malware, which exposed credentials granting read-only access to attacker-controlled GitHub repositories tied to the PeakyBlindersTeam account. Those repositories held initial system check-ins, host data, and commands sent to selected compromised machines, letting researchers connect the threat actor’s command-and-control infrastructure to the hands-on activity of the operators.
Dream’s involvement with that infrastructure was strictly passive. The researchers didn’t alter or erase anything in the repositories, nor did they send commands to any compromised system.
The probe further surfaced infrastructure built to spoof government and regional bodies. Phishing pages recovered in the operation mimicked the Kuwait Ministry of Foreign Affairs and the GCC Secretariat General, while other setup used themes tied to the Kurdistan Regional Government and its Ministry of Electricity. The Kuwait and GCC discoveries point to impersonation and targeting infrastructure, but Dream stressed that there’s no evidence either institution was actually breached.
Dream linked this latest wave to four earlier phases documented by Elastic Security Labs, Unit 42, and Group-IB, establishing a through-line across five distinct waves of the campaign.
Looking at the infrastructure, malware design, operator behavior, and who was targeted, Dream said it assesses with high confidence that this activity comes from an Iranian threat actor and belongs to the DarkBlinders or Blinder Tunnel cluster. The company separately gauges with medium-to-high confidence that the wider activity cluster connects to operations tracked as UNC5795 and UNC5187.
The investigation leaned on Dream’s agentic Campaigner system. Its Pivoter agent helped organize existing threat intelligence and map out infrastructure connections, while the Malware Agent handled static and dynamic analysis of the malicious software. Dream’s human researchers reviewed and verified the findings and carried out the repository and malware inspection detailed in the report.
The full technical report ships with indicators of compromise and practical guidance for organizations looking to spot the campaign’s credential-phishing infrastructure, persistence tricks, and command-and-control traffic.
Read the full report here.
About Dream
Dream builds sovereign AI and cybersecurity technologies for governments and critical infrastructure. Designed for secure, mission-critical settings, Dream pairs specialized AI systems with cybersecurity know-how to help governments understand, investigate, and defend against sophisticated threats while keeping control of their own data and infrastructure.
Read more: www.dreamgroup.com
Media contact: media@dreamgroup.com
Raoul Wootliff
N10S
+972 546921720
Why it matters
This disclosure shows that state-linked espionage groups are actively refining their tactics, using fake meeting apps and credential traps to slip into government networks — and they’re being selective about which victims to exploit fully. For organizations in government and critical infrastructure, the takeaway is clear: phishing defenses and endpoint monitoring need to account for attackers who linger and pick their moments, not just automated broad-stroke intrusions.