Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware

A campaign that targeted Iraqi government personnel by posing as the country’s Ministry of Foreign Affairs and delivering a collection of never-before-seen malware has been linked to a suspected Iran-nexus threat actor.

The cluster is being tracked under the name Dust Specter by Zscaler ThreatLabz, which noticed the activity in January 2026. The attacks result in the spread of malware such as SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. They take the shape of two distinct infection chains.

According to security researcher Sudeep Singh, Dust Specter employed randomly generated URI pathways for command-and-control (C2) communication, with checksum values applied to the URI paths to guarantee that these requests came from an actual compromised system. Additionally, the C2 server used User-Agent verification and geofencing techniques.

The campaign’s use of evasion tactics to postpone execution and evade detection, as well as the breach of Iraqi government-related infrastructure to stage harmful payloads read more about Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *