logo

Iran-nexus APT Dust Specter targets Iraq officials with new malware

ID: a31f0a8a-4f55-5ce0-94bc-73e341f8dc53

STIX ID: report--a31f0a8a-4f55-5ce0-94bc-73e341f8dc53

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Zscaler ThreatLabz observed a January 2026 campaign attributed with medium-to-high confidence to the Iran-linked APT Dust Specter targeting Iraqi government officials via spear-phishing that delivered new .NET malware families (SPLITDROP, TWINTASK, TWINTALK, GHOSTFORM) using password-protected archives, DLL sideloading, in-memory execution, and ClickFix-style lures; the report details two attack chains, C2 techniques, persistence mechanisms, IOCs, and notes possible generative-AI involvement in the malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.