Assessed by Zscaler ThreatLabz with medium-to-high confidence to be an Iran-nexus APT group, based on overlapping TTPs, victimology (Iraqi government targeting), lightweight custom .NET tooling with minimal obfuscation, and lure themes consistent with previously observed Iran-linked cyber-espionage operations. "Dust Specter" is Zscaler's internal tracking designation; the group has not been publicly linked to a named, previously catalogued Iranian cluster (e.g., no confirmed overlap published with MuddyWater, APT34/OilRig, etc.), so attribution to a specific Iranian sponsor remains uncertain.
Origin
Iran
First seen
2025-07 (earliest related ClickFix activity reusing the same C2 domain; primary campaign observed January 2026)
Last active
2026-01
Motivation
Cyber-espionage / intelligence collection against government targets
Attribution confidence
medium
MENA targeting
Iraq
Sectors
Government, Ministry of Foreign Affairs
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Iraq (Government, Ministry of Foreign Affairs sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Tasking and file-upload payloads are Base64-encoded with a random character prepended (command type 2 upload; in.txt commands skip the first character).
TWINTALK/GHOSTFORM beacon over HTTPS GET with random 10-hex-char URI plus 6-char checksum, JWT bearer carrying bot ID, Chrome/135 User-Agent, 120s base delay with jitter; server enforces geofencing and User-Agent checks.
SPLITDROP decrypts embedded resource CheckFopil.PolGuid.zip with AES-256-CBC using a PBKDF2 (HMAC-SHA1, 10,000 iterations) key before extracting the payload.
TWINTASK sideloaded as libvlc.dll by legitimate vlc.exe and TWINTALK as hostfxr.dll by WingetUI.exe (Zscaler mapped as DLL side-loading, T1574.002 now merged into T1574.001).
SPLITDROP .NET dropper disguised as WinRAR prompts the victim for the archive password before decrypting and staging payloads to C:\ProgramData\PolGuid\.
TWINTASK polls C:\ProgramData\PolGuid\in.txt every 15s and runs Base64-decoded commands via PowerShell; GHOSTFORM executes PowerShell scripts entirely in memory.
Second chain used ClickFix-style fake Cisco Webex meeting invitations on meetingapp[.]site instructing victims to run PowerShell commands (Zscaler ATT&CK table).
Regional co-occurrence is association, not prediction. These techniques appeared alongside Dust Specter's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 6 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAnti-SpoofingT1566significantMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.001partialRole Based Access ControlT1059minimalAntimalwareT1059significantAntimalwareT1059.001significantAntimalwareT1204significantAntimalwareT1204.002significantAntimalwareT1566significantAntimalwareT1566.001significantAnti-PhishingT1566significantAnti-PhishingT1566.001significantAntiSpamT1566significantAntiSpamT1566.001significant
detect · 7 techniques
Adaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantApp GovernanceT1566significantAdvanced Threat HuntingT1566significantDefender for Cloud AppsT1071minimalMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1059.001minimalMicrosoft Defender for IdentityT1071minimalPreset Security PoliciesT1204significantPreset Security PoliciesT1566significantPreset Security PoliciesT1566.001significant
respond · 6 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantQuarantine PoliciesT1566significantQuarantine PoliciesT1566.001significantSafe AttachmentsT1204significantSafe AttachmentsT1204.002significant
Countermeasures · D3FEND
Defensive techniques that counter Dust Specter's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.