Dust Specter is a suspected Iran-nexus advanced persistent threat actor associated with targeted espionage operations against Iraqi government personnel. The group was publicly identified in connection with a January 2026 campaign that impersonated Iraq’s Ministry of Foreign Affairs to target government officials and diplomats. Activity attributed to Dust Specter has been assessed with medium-to-high confidence as aligned with Iranian interests based on victimology, tradecraft, and operational overlap with broader Iranian threat activity. Dust Specter is notable for using previously undocumented malware families including SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. In one infection chain, a .NET dropper masquerading as legitimate software decrypted and deployed modular payloads, after which the operators abused DLL sideloading through trusted applications to execute follow-on components. TWINTASK functioned as a worker component for local command execution, including PowerShell-based tasking, while TWINTALK acted as the command-and-control orchestrator, supporting script execution, file transfer, and additional payload delivery. Another chain used GHOSTFORM, a more consolidated implant that executed commands largely in memory and displayed a fake government-themed survey lure to distract victims. The actor’s tradecraft includes spearphishing, government impersonation, spoofing, persistence via autorun mechanisms, DLL sideloading, in-memory execution, and defense-evasion features such as delayed execution, mutex checks, randomized beacon timing, and customized command-and-control request patterns. Dust Specter has also used ClickFix-style social engineering lures themed as online meeting invitations to induce victims to run malicious PowerShell commands. Researchers also noted code artifacts in some Dust Specter malware consistent with possible AI-assisted development, including unusual Unicode and emoji elements, though the operational significance of that observation is limited. Current public reporting supports Dust Specter primarily as an Iran-aligned espionage actor focused on Iraqi government targets rather than a ransomware or financially motivated intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-nexus espionage actor targeting Iraqi government officials with impersonation lures and novel malware families delivered through DLL sideloading and in-memory execution.
APT activity reported targeting government officials in Iraq.
Targeting Iraqi government officials using newly reported malware (espionage-oriented activity implied by victimology).
Suspected Iran-nexus campaign targeting Iraqi government officials; uses compromised Iraq-related infrastructure for hosting payloads; employs C2 request validation (checksums), geofencing and User-Agent verification; tooling includes .NET droppers/RAT with in-memory PowerShell execution and evasion via delayed execution/invisible forms; report notes possible generative-AI-assisted development.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.