Fake Dubai Airports Recruiters Push Dev Malware

Unit 42 · High sophistication
Last updated October 7, 2026

Researchers reported an Iranian state-aligned actor impersonating the Dubai Airports IT department to lure a targeted Iraqi individual into installing a fake “careers portal” and then opening a weaponized coding test. The workflow looked like a real recruitment process (HR questions, then a developer assessment) but ultimately delivered malware when the victim opened a trojanized Visual Studio project.

How the attack worked

The operation unfolded as a staged, multi-step recruitment process rather than a single malicious email. The target, described as an Iraqi individual, was approached with a job offer for a development role, with attackers impersonating the Dubai Airports IT department. As a mandatory first stage, the target was instructed to download and install a file named Dubai Airport Careers, effectively a fake careers portal used to establish initial access and build legitimacy.

Once the target progressed further, the attackers sent a coding assessment: a weaponized Microsoft Visual Studio project archive named DubaiAirport_Carrers_IT_Test.zip, with Carrers misspelled instead of Careers. The archive included a Readme.md with personalized instructions addressed directly to the target by name. The malicious code was embedded in a .csproj file, meaning it could execute as soon as the project loaded in an IDE, before the victim ever compiled or ran the code.

Why it succeeded

The early stages of the workflow, such as the careers portal and an HR-style questionnaire, did not trigger data exfiltration or malicious execution. This lack of suspicious activity appears to have been intentional, designed to build credibility and lower the victim's guard before the actual payload arrived in a later phase. By the time the weaponized project file showed up, the target had already engaged in what looked like a normal, multi-step hiring process.

The campaign also misused GitHub's API infrastructure for command-and-control communication, allowing malicious traffic to blend in with legitimate cloud and developer activity rather than standing out on a network.

What to watch for

  • Unsolicited job offers requiring software installation as a mandatory first step
  • Login credentials supplied directly by recruiters rather than through a normal sign-up flow
  • Coding assessments delivered as zip archives rather than through standard testing platforms
  • Slight misspellings in file or archive names, such as Carrers instead of Careers
  • Personalized messages referencing a target's full name to build trust before a payload is delivered

Building resistance

Organizations can reduce exposure to this type of lure by training developers and engineers to treat unsolicited recruitment outreach that requires installing software or opening project files as high risk, and to verify such requests through official company channels first. Coding challenges and project files from unknown sources should go through a safe review process, such as an isolated environment, rather than being opened directly in a developer's primary IDE. Security teams should also watch for unusual GitHub API activity tied to downloads or key usage, since legitimate cloud services can be abused to mask command-and-control traffic within normal enterprise activity.

Key findings

  • Actor impersonated the “Dubai Airports IT department” and ran a staged recruitment workflow (career portal then coding test).
  • Victim was instructed to install “Dubai Airport Careers” and later open a weaponized Visual Studio project archive “DubaiAirport_Carrers_IT_Test.zip”.
  • The coding test used a malicious .csproj so the payload executed when the project was loaded in the IDE (before compiling).
  • Campaign misused GitHub’s API/repositories (including GitHub issues) for command-and-control and hosting/supporting components; GitHub removed identified malicious infrastructure.
  • Unit 42 linked operational mistakes (public repos, infrastructure overlap, embedded metadata) to other activity including “conflict-themed Google Drive lures for credential harvesting against an Israeli entity.”

Who’s being targeted

  • Commonly targeted roles: Software engineers, Developers, Engineering managers, IT and Security leadership, Critical infrastructure staff.
  • Affected industries: Critical infrastructure, Telecommunications, Aviation.
  • Attack channels: email.
  • Impersonated: Dubai Airports IT department (recruiters), Senior manager, Dubai Airports IT department.

Red flags to watch for

  • Being asked to install software as a “mandatory first stage” of a job process
  • Login credentials are “provided by the recruiters” rather than using a normal sign-up flow
  • Employer brand used to justify installing an offline portal/app
  • Archive name misspelling: “DubaiAirport_Carrers_IT_Test.zip”
  • Pressure to open and run/build code from an untrusted source
  • “Personalized instructions” that attempt to increase trust and urgency
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake Dubai Airports recruiter attack work?

An actor impersonating the Dubai Airports IT department ran a staged recruitment workflow, first having the target install a fake careers portal, then sending a weaponized Visual Studio project disguised as a coding assessment.

What made the malicious file hard to spot?

The payload was delivered through a .csproj file inside a zip archive named DubaiAirport_Carrers_IT_Test.zip, which executed when the project loaded in an IDE, before the victim even compiled the code.

Why did the victim trust the process?

Early steps like the careers portal and questionnaire did not trigger any suspicious activity, which was designed to build credibility and lower the victim's guard before the malicious payload arrived later.

Was any legitimate service abused in this campaign?

Yes, the campaign misused GitHub's API infrastructure for command-and-control communication to blend malicious traffic with normal cloud activity.

Read the video transcript

You get an email: “Dear , I’m from the Dubai Airports IT department with a developer role for you.” Sounds legit, right? They walk you through a fake careers portal, then send a “mandatory first stage” installer called Dubai Airport Careers. Next, a Visual Studio zip: DubaiAirport_Carrers_IT_Test.zip, a coding test that’s actually malware. Here’s the trick: the malicious .csproj runs as soon as you load it in Visual Studio. No build, no run button, just opening the project can hand over access, with traffic hiding inside normal GitHub API calls. If any “recruiter” asks you to install software or open a coding test ZIP, stop. Before you touch it, verify the job through the company’s official careers site or HR contact.

Similar attacks

Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
Resume Phish Hit Brazil Banks; AI Aided Ops

Resume Phish Hit Brazil Banks; AI Aided Ops

Two real, ongoing intrusion campaigns targeted organizations in Latin America, including a Mexican transportation organization and Brazil’s financial sector. In the Brazil campaign, attackers reportedly got in via a resume-themed phishing attachment, then attempted to download and run tunneling…

September 3, 2026
SilkParasite Uses Ministry-Themed Phishing to Drop RATs

SilkParasite Uses Ministry-Themed Phishing to Drop RATs

Researchers reported a real espionage campaign (“SilkParasite”) targeting Central Asian government bodies using spear‑phishing emails. The attack uses password‑protected RAR files containing malicious Microsoft Office documents; when opened, macros trigger a DLL sideloading chain to install remote…

August 19, 2026
Placeholder Domain Now Pushes ClickFix Malware

Placeholder Domain Now Pushes ClickFix Malware

A commonly used documentation placeholder domain, third-party.com, was registered by an unknown party and is now serving a ClickFix social-engineering lure to Windows users. The page pretends to run a Cloudflare security check, silently poisons the clipboard, and tells victims to paste and run a…

September 24, 2026
Fake LastPass GitHub Drops Rapuncel Stealer

Fake LastPass GitHub Drops Rapuncel Stealer

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets,…

September 23, 2026