In January 2026, Zscaler’s ThreatLabz team identified a sophisticated cyber attack attributed to the Iranian-linked APT group, known as Dust Specter, targeting government officials in Iraq.
The campaign used custom malware, including previously unknown tools such as SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM.
These tools and tactics demonstrated a high level of sophistication, incorporating generative AI in malware development and complex command-and-control (C2) mechanisms.
The attack unfolded in two distinct chains. The first involved a SPLITDROP dropper, which distributed TWINTASK and TWINTALK backdoors, while the second utilized GHOSTFORM, a remote access trojan (RAT) that consolidated functionalities from the previous tools.
These attack chains employed various evasion and persistence techniques to maintain prolonged access to compromised systems.
Attack Chain 1: SPLITDROP was delivered in a password-protected RAR archive disguised as a legitimate file from Iraq’s Ministry of Foreign Affairs.
Upon execution, SPLITDROP dropped two modules: TWINTASK, a worker module that ran PowerShell scripts, and TWINTALK, a C2 orchestrator.
These modules used file-based polling for communication, ensuring that commands were executed without detection. TWINTASK also maintained persistence by modifying registry entries, allowing the malware to run upon system restart.
_imresizer.webp)
C:\programData\PolGuid\ after extraction (Source: zscaler)Attack Chain 2: The second attack chain relied on GHOSTFORM, which consolidated the functionality of TWINTASK and TWINTALK into a single binary.
Unlike the first chain, GHOSTFORM used in-memory PowerShell execution, reducing the attack’s footprint on the filesystem.
It employed creative evasion techniques, including an invisible Windows form with a delayed execution timer, which made detection more challenging.
AI‑Assisted Malware Development
One of the most notable aspects of the Dust Specter campaign was the integration of generative AI in the development of the malware.
Code analysis revealed unusual patterns, such as the use of emojis and Unicode text, strongly suggesting the use of AI tools in crafting the malware. This trend of using AI to develop more sophisticated and evasive malware is becoming increasingly common among threat actors.
ThreatLabz attributes this campaign to Dust Specter with moderate confidence, based on the code, victimology, and attack patterns.

Zscaler victimology aligns with past targets of Iran-nexus groups, particularly within the Iraqi government sector. Additionally, the use of compromised Iraqi infrastructure for hosting malicious payloads and C2 communication mirrors tactics used by Iranian APT groups in previous attacks.
This campaign highlights the evolving nature of cyber threats, where AI-assisted malware development is increasingly becoming a tool of choice for advanced persistent threats.
Organizations must remain vigilant and adopt robust security measures to defend against these sophisticated attack strategies.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.