An Iran-nexus threat operation tracked as Dust Specter impersonated Iraq’s Ministry of Foreign Affairs to compromise Iraqi government officials using multiple newly identified malware families: SplitDrop, TwinTask, TwinTalk, and GhostForm. Reporting indicates the activity was first identified in January and used at least two delivery chains: (1) a password-protected RAR archive containing a WinRAR-spoofing .NET dropper (SplitDrop) that decrypts and deploys follow-on payloads, and (2) a GhostForm chain that abuses a Google Forms-themed lure and executes PowerShell in memory.
Technical details described include TwinTask polling for commands and enabling PowerShell-based execution, while TwinTalk communicates with a C2 server for tasking. Researchers also noted development artifacts consistent with generative AI-assisted coding, including emojis/unicode in source code and other “placeholder”-style patterns, suggesting AI may have been used to produce functional malicious code rather than only support planning or content generation. Attribution was assessed with medium-to-high confidence to an Iran-linked actor based on overlaps in victimology and tradecraft with known Iranian APT activity.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
When reporting the campaign in early March 2026, Zscaler ThreatLabz said code artifacts in TWINTALK and GHOSTFORM suggested possible generative-AI assistance in malware development. Reported indicators included emoji and Unicode patterns and a placeholder seed value in the code.
Following analysis of the January 2026 intrusions, Zscaler ThreatLabz assessed with medium-to-high confidence that Dust Specter is linked to an Iran-nexus threat actor. The attribution was based on overlaps in tooling, techniques, infrastructure, and victimology.
During the January 2026 campaign, Dust Specter delivered previously undocumented malware named SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. One chain used a password-protected RAR and DLL sideloading through legitimate binaries, while the other used a single-binary GHOSTFORM implant with in-memory PowerShell execution and a fake Arabic Google Form lure.
In January 2026, attackers tracked as Dust Specter targeted Iraqi government officials by impersonating Iraq’s Ministry of Foreign Affairs in social-engineering lures. The campaign used compromised Iraqi government-related infrastructure to stage payloads.
In July 2025, infrastructure later linked to Dust Specter was used in a ClickFix-style campaign impersonating a Cisco Webex Government meeting invite. Victims were tricked into running PowerShell that downloaded a payload and established persistence via a scheduled task.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.