logo

Iran‑Linked “Dust Specter” APT Deploys AI‑Aided Malware Against Iraqi Officials

ID: 4a6a2ecd-a69d-5f6b-858d-03a7d142b0c9

STIX ID: report--4a6a2ecd-a69d-5f6b-858d-03a7d142b0c9

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Dust Specter, assessed as an Iran‑nexus APT, ran a January 2026 campaign against Iraqi government officials using custom .NET malware families (SPLITDROP, TWINTASK, TWINTALK) and a consolidated RAT (GHOSTFORM) delivered via passworded archives and social‑engineering lures; tactics include DLL sideloading, in‑memory PowerShell, JWT‑based C2, and reuse of infrastructure tied to a July 2025 ClickFix operation. The report includes detailed behavioral analysis and a list of network IOCs (domains and URLs) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.