Iranian hackers are reportedly linked to a campaign targeting government officials in Iraq. The attackers are impersonating the Ministry of Foreign Affairs to deliver a set of malware. Zscaler ThreatLabz, which observed the activity in January 2026, tracks the group under the name Dust Specter. The attacks manifest in the form of two distinct infection chains, culminating in the deployment of malware named SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM.

“Dust Spectre used randomly generated URI paths for command and control (C2) communication, with checksum values added to the URI paths to ensure that these requests were coming from a truly infected system,” said security researcher Sudeep Singh. “The C2 server also used geofencing techniques and User-Agent verification.”
A notable element of the campaign is the breach of infrastructure associated with the Iraqi government for staging malicious payloads, along with the use of evasion techniques to delay execution and remain in the system (undetected).
See also: Ukraine: APT28 installs BadPaw Loader and MeowMeow Backdoor
Dust Specter: Different infection chains
The first attack chain starts with a RAR filecontaining a .NET dropper called SPLITDROP. This acts as a conduit for TWINTASK, a worker module, and TWINTALK, a C2 orchestrator.
TWINTASK is a malicious DLL (“libvlc.dll”), loaded by the legitimate “vlc.exe” binary to periodically check a file (“C:\ProgramData\PolGuid\in.txt”) every 15 seconds. It checks for new commands and executes them using PowerShell. Commands are included to establish persistence on the host computer via changes to the Windows Registry. The script output and errors are logged in a separate text file (“C:\ProgramData\PolGuid\out.txt”).
Upon first launch, TWINTASK executes another legitimate binary contained in the exported file (“WingetUI.exe”), causing the TWINTALK DLL (“hostfxr.dll”) to be loaded. Its main purpose is to communicate with the C2 server for new commands, coordinate tasks with TWINTASK, and output the results back to the server. It supports the ability to write the command body from the C2 response to “in.txt”, as well as download and upload files.

“The C2 orchestrator works in parallel with the aforementioned worker module to implement a file control mechanism used for code execution,” Singh said. “During execution, TWINTALK enters a beaconing loop and delays execution before checking the C2 server for new commands.”
See also: Middle East war: 149 DDoS attacks “hit” 110 organizations
The second attack chain represents an evolution of the first, consolidating all the functionality of TWINTASK and TWINTALK into a single binary called GHOSTFORM . It uses in-memory PowerShell script execution to execute commands retrieved from the C2 server, thus eliminating the need to write objects to disk.
Some GHOSTFORM binaries embed a hard-coded Google Forms URL, which is automatically launched in the system's default browser once the malware starts executing. The form contains content written in Arabic and pretends to be an official survey from the Iraqi Ministry of Foreign Affairs.
Zscaler analyzed the source code of TWINTALK and GHOSTFORM and identified placeholder values, emojis, and Unicode text. This suggests that generative AI tools to aid in the development of the malware.
The C2 domain associated with TWINTALK, “meetingapp[.]site”, is said to have been used by Dust Specter in a campaign in July 2025.
The PowerShell script creates a directory on the host and attempts to retrieve a payload from the same domain and save it as an executable. It also creates a scheduled task to execute the malicious binary every two hours.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Dust Specter's connections to Iran are based on the fact that Iranian hacking groups have a history of developing custom lightweight .NET backdoors to achieve their goals. Additionally, the use of compromised Iraqi government infrastructure has been observed in previous campaigns associated with threat actors such as OilRig (also known as APT34).
See also: Malicious Laravel Packages on Packagist Install RAT
"This campaign, attributed with medium to high certainty to Dust Specter, likely targeted government officials using convincing social engineering decoys impersonating the Iraqi Ministry of Foreign Affairs," Zscaler said.
