Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
A campaign that targeted Iraqi government personnel by posing as the country's Ministry of Foreign Affairs and delivering a collection of never-before-seen malware has been linked to a suspected Iran-nexus threat actor.
The cluster is being tracked under the name Dust Specter by Zscaler ThreatLabz, which noticed the activity in January 2026. The attacks result in the spread of malware such as SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. They take the shape of two distinct infection chains.
According to security researcher Sudeep Singh, Dust Specter employed randomly generated URI pathways for command-and-control (C2) communication, with checksum values applied to the URI paths to guarantee that these requests came from an actual compromised system. Additionally, the C2 server used ...

