Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs

In January 2026, a cyberattack targeting government officials in Iraq was identified. The threat group, known as Dust Specter, impersonated Iraq’s Ministry of Foreign Affairs to deceive targets into downloading malicious files.

In January 2026, a cyberattack targeting government officials in Iraq was identified. The threat group, known as Dust Specter, impersonated Iraq’s Ministry of Foreign Affairs to deceive targets into downloading malicious files.

The attack introduced four new malware tools: SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. These tools suggest the involvement of a state-linked actor due to their sophistication. Researchers attribute this to an Iran-nexus threat actor based on similarities with known Iranian APT groups.

The initial attack chain involved a RAR archive named mofa-Network-code.rar , disguised as an official document. Upon opening, a .NET binary, SPLITDROP, decrypted an embedded payload using AES-256 encryption, dropping malicious files on the victim's machine while displaying a false error message.

The second attack chain utilized GHOSTFORM, which presented a fake Arabic Google Form survey while malware executed undetected.

Research indicates the use of AI in developing the malware, with evidence such as emojis and unicode characters in the source code of TWINTALK and GHOSTFORM, and a hardcoded seed value linked to AI-generated code.

In January 2026, a cyberattack targeting government officials in Iraq was identified.
Omar Sabbagh · The Levant Herald

This signifies a shift where AI is used not only for planning but also for writing functional malicious code.

The same group is linked to a ClickFix-style attack from July 2025, which involved a webpage mimicking a Cisco Webex Government meeting invitation, leading victims to execute a PowerShell command that downloaded a malicious binary.

Technical Exploits: DLL Sideloading and Persistence

In the first attack chain, SPLITDROP extracted its payload and launched VLC Media Player, which sideloaded a malicious DLL named libvlc.dll . This technique exploits the trust placed in recognized applications and does not require elevated privileges.

TWINTASK, the malicious DLL, polled a local text file for Base64-encoded PowerShell commands from the C2 orchestrator. It then launched WingetUI.exe, which sideloaded another malicious DLL, hostfxr.dll, acting as the C2 orchestrator.

Advertisement

To verify requests, TWINTALK generated dynamic URI paths with checksums, and the C2 server applied geofencing to restrict responses to specific regions.

Persistence was achieved via Windows Registry Run keys, ensuring the relaunch of VLC.exe and WingetUI.exe after system restarts. GHOSTFORM delayed its execution by launching an invisible Windows form.

Implement strict application allowlisting to prevent unauthorized DLL sideloading. Configure email and web gateways to block password-protected archives from unverified sources. Enable PowerShell script block logging and monitor Windows Registry Run keys for unexpected entries. Flag outbound HTTPS traffic with randomized URI patterns and non-standard JWT authorization headers.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories