Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
ID: 60b7dbc3-92c7-5f72-b4e4-4af76de46371
STIX ID: report--60b7dbc3-92c7-5f72-b4e4-4af76de46371
Feed Name: The Hacker News
A suspected Iran-nexus APT cluster called Dust Specter targeted Iraqi government officials using social-engineered lures impersonating the Ministry of Foreign Affairs to deliver novel .NET malware families (SPLITDROP, TWINTASK, TWINTALK) and an evolved single-binary implant (GHOSTFORM). The campaign used compromised Iraqi infrastructure to host payloads, file- and fileless execution paths (including in-memory PowerShell), C2 evasion (randomized URIs, checksums, geofencing, User-Agent validation), and reuse of domains tied to prior campaigns; Zscaler attributes the activity with medium-to-high confidence and notes possible generative-AI assistance in malware development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
