logo

Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware

ID: 60b7dbc3-92c7-5f72-b4e4-4af76de46371

STIX ID: report--60b7dbc3-92c7-5f72-b4e4-4af76de46371

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-03-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A suspected Iran-nexus APT cluster called Dust Specter targeted Iraqi government officials using social-engineered lures impersonating the Ministry of Foreign Affairs to deliver novel .NET malware families (SPLITDROP, TWINTASK, TWINTALK) and an evolved single-binary implant (GHOSTFORM). The campaign used compromised Iraqi infrastructure to host payloads, file- and fileless execution paths (including in-memory PowerShell), C2 evasion (randomized URIs, checksums, geofencing, User-Agent validation), and reuse of domains tied to prior campaigns; Zscaler attributes the activity with medium-to-high confidence and notes possible generative-AI assistance in malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.