As cited
Copy frozen at (site build).
threat intel
Dust Specter APT Targets Government Officials in Iraq
In January 2026, security researchers at Zscaler ThreatLabz identified a campaign by suspected Iran-nexus threat actor Dust Specter targeting Iraqi government officials through impersonation of the Ministry of Foreign Affairs. The attack deployed four previously undocumented malware families: SPLITDROP (a .NET dropper), TWINTASK and TWINTALK (backdoor modules using DLL sideloading), and GHOSTFORM (a remote access trojan consolidating the previous payloads). The campaign leveraged compromised Iraqi government infrastructure to host malicious archives, social engineering lures mimicking Cisco Webex and Google Forms, and ClickFix techniques to trick victims into executing PowerShell commands.
Why it matters: Iraqi government officials, particularly those in the Ministry of Foreign Affairs, face targeted compromise via convincing spear-phishing; practitioners managing networks in the region or supporting government endpoints should audit for these specific malware indicators, suspicious DLL sideloading of legitimate applications like VLC and WingetUI, and Registry persistence mechanisms.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Dust Specter APT Targets Government Officials in Iraq
In January 2026, security researchers at Zscaler ThreatLabz identified a campaign by suspected Iran-nexus threat actor Dust Specter targeting Iraqi government officials through impersonation of the Ministry of Foreign Affairs. The attack deployed four previously undocumented malware families: SPLITDROP (a .NET dropper), TWINTASK and TWINTALK (backdoor modules using DLL sideloading), and GHOSTFORM (a remote access trojan consolidating the previous payloads). The campaign leveraged compromised Iraqi government infrastructure to host malicious archives, social engineering lures mimicking Cisco Webex and Google Forms, and ClickFix techniques to trick victims into executing PowerShell commands.
Why it matters: Iraqi government officials, particularly those in the Ministry of Foreign Affairs, face targeted compromise via convincing spear-phishing; practitioners managing networks in the region or supporting government endpoints should audit for these specific malware indicators, suspicious DLL sideloading of legitimate applications like VLC and WingetUI, and Registry persistence mechanisms.
- Source published
- First seen by Cybersecurity Tracker