Dust Specter is an Iran-nexus cyberespionage threat actor targeting Iraqi government officials and diplomatic personnel. Publicly identified by Zscaler ThreatLabz in March 2026, the group conducted a January 2026 phishing campaign impersonating Iraq’s Ministry of Foreign Affairs. Its delivery infrastructure included compromised Iraqi government-related resources. Associated activity dates to July 2025, when a ClickFix-style lure impersonated a Cisco Webex government meeting invitation and induced victims to execute malicious PowerShell commands. The group uses the custom malware families SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. One infection chain delivers a password-protected archive containing SPLITDROP, a .NET dropper masquerading as WinRAR, which decrypts and deploys TWINTASK and TWINTALK. These components abuse legitimate VLC and WingetUI applications for DLL sideloading. TWINTASK executes PowerShell commands, while TWINTALK orchestrates command-and-control communications and supports script execution, file uploads, and additional payload downloads. Persistence mechanisms include Windows Registry Run keys and scheduled tasks. GHOSTFORM consolidates remote-access functionality into a single implant, displays a fake government survey using a Google Forms lure, and executes commands in memory to reduce filesystem traces. Dust Specter’s evasion techniques include randomized beacon intervals, dynamically generated request paths, JWT-based communications, geofenced server responses, and delayed execution using invisible Windows forms. Its established targeting centers on Iraqi governmental and diplomatic intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with meeting-service and commercial-themed command-and-control infrastructure and the GHOSTFORM malware sample, also classified as TREEWORLD. Exact malware matches and infrastructure associations connect its examined operations to UNC5795 with medium-to-high confidence. Supporting research reports overlap with TAG-135, an APT34 subcluster.
Iran-nexus espionage actor targeting Iraqi government officials with impersonation lures and novel malware families delivered through DLL sideloading and in-memory execution.
APT activity reported targeting government officials in Iraq.
Targeting Iraqi government officials using newly reported malware (espionage-oriented activity implied by victimology).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.