216.73.217.80

Dust Specter APT Targets Government Officials in Iraq

· Published 02/03/2026 17:44 · Modified 03/03/2026 17:14

Export JSON

Essential information

Published
02/03/2026 17:44
Modified
03/03/2026 17:14
Tags
2026-03-02 apt clickfix generative ai ghostform government iran-nexus iraq social engineering splitdrop twintalk twintask
Related entities
15 observables, 1 intrusion sets (apt), 8 techniques (mitre), 4 malware, 9 others

Description

A suspected threat actor, dubbed Dust Specter, targeted Iraqi officials in January 2026. The campaign involved impersonating 's Ministry of Foreign Affairs and using compromised infrastructure to host malicious payloads. Two attack chains were identified, utilizing previously undocumented malware including , , , and . The malware employed creative evasion techniques, leveraged for development, and used file-based polling mechanisms for command execution. The campaign also incorporated -style attacks and lures. Attribution to an group is based on code similarities, victimology, and overlapping tactics with known Iranian groups.

External references