Dust Specter is a suspected Iran-nexus advanced persistent threat group tracked by Zscaler ThreatLabz. It was documented in a March 2026 report describing a targeted espionage campaign against Iraqi government officials in which the actor impersonated Iraq's Ministry of Foreign Affairs to deliver previously undocumented custom .NET malware (SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM). The campaign is notable for combining social-engineering lures (fake Iraqi government surveys, ClickFix-style delivery), compromised legitimate Iraqi infrastructure, and code artifacts suggesting the operators experimented with generative-AI-assisted malware development.
Zscaler ThreatLabz first documented Dust Specter publicly in a blog dated March 2, 2026. The primary campaign was observed in January 2026, targeting government officials in Iraq, with earlier related ClickFix activity reusing the same C2 domain traced back to July 2025. The actor impersonated Iraq's Ministry of Foreign Affairs and used fake Google Forms posing as Iraqi government surveys as lures. Two distinct attack chains were observed. Chain 1 used SPLITDROP, a .NET dropper masquerading as a WinRAR application that decrypts an AES-256 embedded payload and deploys TWINTASK (a worker DLL that polls for commands via file-based in.txt/out.txt mechanisms) and TWINTALK (a C2 orchestrator managing beaconing); GHOSTFORM is a consolidated single-binary .NET RAT combining Chain 1 functionality with in-memory PowerShell execution. Delivery relied on password-protected RAR archives, DLL sideloading via legitimate signed binaries (VLC.exe, WingetUI.exe), and ClickFix-style PowerShell injection. Notable tradecraft includes randomized C2 URI paths with custom checksums, server-side JSON key randomization to defeat signature matching, JWT tokens carrying bot IDs in the 'iat' header field, HTTPS beacons randomized to 108-180 seconds, geofencing and User-Agent validation on C2 servers, invisible Windows forms (0.001 opacity) for delayed execution, and Run-registry-key persistence pointing at sideloaded DLLs. Infrastructure abuse was confirmed: the legitimate Iraqi government website ca.iq was compromised and used to host the malicious archive. Code artifacts (embedded emojis/Unicode and a 0xABCDEF placeholder seed) led ThreatLabz to assess that generative-AI tools were likely used during malware development. MENA relevance: HIGH and REAL. Iraq-targeting is the central, well-documented fact of the only public reporting on this actor — the campaign specifically targeted Iraqi government officials, impersonated Iraq's Ministry of Foreign Affairs, and abused compromised Iraqi (.iq) government infrastructure. The existing RaqibCTI 'Iraq' country tag is fully corroborated by primary-source (Zscaler ThreatLabz) reporting. Attribution to Iran (an Iran-nexus actor operating against a neighboring MENA state) further strengthens the regional relevance, though the specific Iranian sponsor cluster remains unidentified.