Iran-nexus APT Dust Specter targets Iraq officials with new malware
ID: a31f0a8a-4f55-5ce0-94bc-73e341f8dc53
STIX ID: report--a31f0a8a-4f55-5ce0-94bc-73e341f8dc53
Feed Name: Security Affairs
Zscaler ThreatLabz observed a January 2026 campaign attributed with medium-to-high confidence to the Iran-linked APT Dust Specter targeting Iraqi government officials via spear-phishing that delivered new .NET malware families (SPLITDROP, TWINTASK, TWINTALK, GHOSTFORM) using password-protected archives, DLL sideloading, in-memory execution, and ClickFix-style lures; the report details two attack chains, C2 techniques, persistence mechanisms, IOCs, and notes possible generative-AI involvement in the malware development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
