Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs
ID: c361d985-f35d-528f-bc92-30b06d64941f
STIX ID: report--c361d985-f35d-528f-bc92-30b06d64941f
Feed Name: cybersecurityNews.com
In January 2026 the Dust Specter APT targeted Iraqi government officials using socially engineered lures (password-protected RAR and fake Google Forms) to deliver four previously undocumented malware tools (SPLITDROP, TWINTASK, TWINTALK, GHOSTFORM); techniques included DLL sideloading via legitimate binaries (VLC, WingetUI), Registry Run key persistence, scheduled tasks, randomized C2 URIs with geofencing, and signs of AI-assisted code generation—researchers attribute the campaign with medium-to-high confidence to an Iran-linked actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
