GHOSTFORM is a .NET-based remote access trojan targeting Windows systems, used by Dust Specter in a January 2026 phishing campaign against Iraqi government officials. The campaign impersonated Iraq’s Ministry of Foreign Affairs and used government-themed social engineering. Some GHOSTFORM samples opened an Arabic Google Forms survey masquerading as an official Ministry questionnaire to distract victims during malicious execution. A GHOSTFORM sample has also been classified as TREEWORLD and associated with the UNC5795 activity cluster.
GHOSTFORM consolidates the command-execution and command-and-control functions of TWINTASK and TWINTALK into a single binary. It retrieves commands from a command-and-control server and executes PowerShell scripts directly in memory, reducing filesystem artifacts. Its combined functionality supports remote command execution and file uploads and downloads. For delayed execution, it uses an effectively invisible Windows form hidden from the taskbar, avoiding delay mechanisms that could attract behavioral-analysis scrutiny. Mutex checks prevent multiple instances from running simultaneously.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The RiroDiog.exe sample documented by Zscaler as GHOSTFORM is classified as TREEWORLD and associated with UNC5795.
The RiroDiog.exe sample documented by Zscaler as GHOSTFORM is classified as TREEWORLD and associated with UNC5795.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
"...ClickFix lure... to trick victims into running malicious PowerShell commands that download and schedule malware execution."
Attack Chain 2 delivered GHOSTFORM, consolidating all functionality into a single binary using an invisible Windows form for delayed execution, in-memory PowerShell command execution
“constructs a unique URI path at runtime… random 10-character hex string… 6-character checksum… server… randomizing JSON key names on each response… parses fields by position rather than by JSON key name.”
"...sideloaded by the legitimate \"vlc.exe\" binary..."; "...masquerades as an official survey from Iraq's Ministry of Foreign Affairs."; "...host a fake Cisco Webex meeting invitation page..."
“Mutex: Creates a mutex with the name Global\_ to ensure that only one instance of GHOSTFORM runs at any given time.”
“launched an invisible Windows form with near-zero opacity, hidden from the taskbar — to delay its own execution”
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware observed in Dust Specter activity. An exact sample match maps GHOSTFORM to Google's TREEWORLD classification and UNC5795 attribution. Its appearance alongside HOTAIR and AEROSTAT in Google's reporting provides additional evidence connecting Dust Specter and DarkBlinders to a common operational cluster. The supplied content does not describe its capabilities.
A single-binary malware family that consolidates Dust Specter functionality, supports in-memory execution, and uses a Google Form lure.
A .NET RAT used by Dust Specter; consolidates functionality and uses in-memory PowerShell execution plus evasion (invisible forms, delayed execution).
Single-binary backdoor that executes attacker commands in-memory to reduce filesystem artifacts; uses social engineering (fake Google Form) and stealth (invisible forms, delayed execution, mutex checks).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.