In January 2026, a suspected Iran-nexus threat actor tracked as Dust Specter launched a targeted cyberespionage campaign against government officials in Iraq. The group impersonated Iraq’s Ministry of Foreign Affairs to distribute previously undocumented malware through two distinct attack chains.
New Malware Strains
The campaign introduced four new, custom-built malware tools that researchers believe were developed using generative AI:
- SPLITDROP: A .NET-based dropper typically delivered in a password-protected RAR archive disguised as a WinRAR binary.
- TWINTASK & TWINTALK: Malicious DLLs dropped by SPLITDROP. TWINTASK handles persistence and polls for PowerShell commands, while TWINTALK acts as the main command-and-control (C2) orchestrator.
- GHOSTFORM: A sophisticated .NET-based Remote Access Trojan (RAT) that consolidates the functionality of the first chain into a single binary, using in-memory execution and invisible Windows forms to evade detection.
Key Tactics & Techniques
- Compromised Infrastructure: The attackers hijacked legitimate Iraqi government infrastructure (including the
ca.iq domain) to host payloads.
- Social Engineering: Dust Specter used “ClickFix” style attacks, tricking victims into pasting malicious PowerShell commands by masquerading as Cisco “Webex for Government” invites.
- Advanced C2 Communication: The servers utilize geofencing and User-Agent verification to ensure only truly infected systems can communicate with them.
Detailed technical analysis of this campaign was first published by security researchers at Zscaler ThreatLabz on March 2, 2026.