logo

Iranian Cyber Threat Actor Targets Iraqi Government Officials in AI-Powered Campaign

ID: 2ec11bc7-0874-59fc-a077-32f689d6cd16

STIX ID: report--2ec11bc7-0874-59fc-a077-32f689d6cd16

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

...
...

An Iran-linked APT referred to as Dust Specter conducted a targeted campaign in January 2026 against Iraqi government officials by impersonating Iraq’s Ministry of Foreign Affairs and hosting malicious payloads on compromised government-related infrastructure. Researchers identified multiple previously undocumented malware families (SplitDrop, TwinTask, TwinTalk, GhostForm), two distinct attack chains (RAR dropper with DLL sideloading and a consolidated .NET RAT using in-memory PowerShell), reuse of C2 infrastructure, social-engineering lures (Webex-style pages and Google Forms), and code artifacts suggesting the use of generative AI in malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.