logo

Dust Specter APT Targets Gov’t Officials in Iraq

ID: 9f775ab8-c0e3-5584-b0a1-e6e68015b345

STIX ID: report--9f775ab8-c0e3-5584-b0a1-e6e68015b345

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-05-01

...
...

This technical analysis describes an active malware campaign with two variants: a split architecture (SPLITDROP drops TWINTASK and TWINTALK) that uses DLL sideloading, file-based command polling, and PowerShell execution, and a single-file variant (GHOSTFORM) that performs in-memory PowerShell execution and uses Google Forms as a social-engineering lure. The report documents persistence via registry Run keys, C2 beaconing with randomized URIs and weak JWT signing, command types (execute/download/upload), multiple evasion techniques (randomized JSON keys, checksum-protected URIs, delayed/invisible execution), and concrete indicators such as file paths and binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.