CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Dust Specter APT Targets Government Officials in Iraq

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6262

As cited

Copy frozen at (site build).

threat intel

Dust Specter APT Targets Government Officials in Iraq

In January 2026, security researchers at Zscaler ThreatLabz identified a campaign by suspected Iran-nexus threat actor Dust Specter targeting Iraqi government officials through impersonation of the Ministry of Foreign Affairs. The attack deployed four previously undocumented malware families: SPLITDROP (a .NET dropper), TWINTASK and TWINTALK (backdoor modules using DLL sideloading), and GHOSTFORM (a remote access trojan consolidating the previous payloads). The campaign leveraged compromised Iraqi government infrastructure to host malicious archives, social engineering lures mimicking Cisco Webex and Google Forms, and ClickFix techniques to trick victims into executing PowerShell commands.

Why it matters: Iraqi government officials, particularly those in the Ministry of Foreign Affairs, face targeted compromise via convincing spear-phishing; practitioners managing networks in the region or supporting government endpoints should audit for these specific malware indicators, suspicious DLL sideloading of legitimate applications like VLC and WingetUI, and Registry persistence mechanisms.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dust Specter APT Targets Government Officials in Iraq

In January 2026, security researchers at Zscaler ThreatLabz identified a campaign by suspected Iran-nexus threat actor Dust Specter targeting Iraqi government officials through impersonation of the Ministry of Foreign Affairs. The attack deployed four previously undocumented malware families: SPLITDROP (a .NET dropper), TWINTASK and TWINTALK (backdoor modules using DLL sideloading), and GHOSTFORM (a remote access trojan consolidating the previous payloads). The campaign leveraged compromised Iraqi government infrastructure to host malicious archives, social engineering lures mimicking Cisco Webex and Google Forms, and ClickFix techniques to trick victims into executing PowerShell commands.

Why it matters: Iraqi government officials, particularly those in the Ministry of Foreign Affairs, face targeted compromise via convincing spear-phishing; practitioners managing networks in the region or supporting government endpoints should audit for these specific malware indicators, suspicious DLL sideloading of legitimate applications like VLC and WingetUI, and Registry persistence mechanisms.

VendorsMicrosoftAppleGoogleCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary