#SplitDrop
Split Drop Review – Is It Legit or a Scam? My Honest Opinion

earn4sure.com/split-drop-r...

#SplitDrop #MakeMoneyOnline #MoneyMakingApps #GPTSites #PaifSurveys
September 23, 2026 at 3:37 PM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
thehackernews.com
March 5, 2026 at 12:28 PM
Dust Specter is targeting Iraqi officials using SPLITDROP & GHOSTFORM malware. Serious cyber threat.

sctocs.com/dust-specter...
Dust Specter Targets Iraqi Officials Using New SPLITDROP And GHOSTFORM Malware - SCtoCS
The Dust Specter threat group is attacking Iraqi government officials with newly developed SPLITDROP and GHOSTFORM malware strains.
sctocs.com
March 5, 2026 at 7:54 PM
A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country's Ministry of Foreign Affairs to deliver a set of never-before-seen malware.
Zscaler ThreatLabz, which observed the activity in January 2026, is tracking ...
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country's Ministry of Foreign Affairs to deliver a set of never-before-seen malware. Zscaler ThreatLabz, which observed the activity in January 2026, is tracking the cluster under the name Dust Specter. The attacks, which manifest in the form of two different
postgoo.com
March 6, 2026 at 5:01 PM
Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs
Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs
In January 2026, a targeted cyberattack emerged against government officials in Iraq. The threat group, tracked as Dust Specter, impersonated Iraq’s Ministry of Foreign Affairs to trick high-value targets into downloading malicious files. The campaign introduced four previously undocumented malware tools — SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM — each reflecting the precision of a seasoned, state-linked actor. Researchers attribute this campaign with medium-to-high confidence to an Iran-nexus threat actor, based on consistent overlaps in tools, techniques, and victim selection with known Iranian APT groups.​ Dust Specter’s first attack chain was delivered through a password-protected RAR archive named mofa-Network-code.rar, disguised as an official Ministry document. When opened, a .NET binary masquerading as a WinRAR application — SPLITDROP — decrypted an embedded payload using AES-256 encryption and dropped malicious files onto the victim’s machine. SPLITDROP displayed a false error message ,  “The download did not complete successfully,”  while operating silently. The second chain used GHOSTFORM, which opened a fake Arabic Google Form survey posing as a government questionnaire while malware ran undetected.​ Google Form Lure (Source – Zscaler) Zscaler ThreatLabz researchers identified fingerprints in the codebase pointing to the use of generative AI during malware development. Emojis and unicode characters embedded inside both TWINTALK and GHOSTFORM source code match a pattern tied to AI-generated programming. A hardcoded seed value of 0xABCDEF — a placeholder found in AI-written code — was also uncovered inside TWINTALK’s checksum generation function. This marks a shift in how threat actors approach development, with AI now used not just for planning but for writing functional malicious code.​ The same group was also connected to a ClickFix-style attack from July 2025, where a webpage mimicking a Cisco Webex Government meeting invitation directed victims to run a PowerShell command. ClickFix Lure (Source – Zscaler) That command downloaded a malicious binary and registered a scheduled task to execute every two hours. Iraq’s Ministry of Foreign Affairs has historically been a priority target for Iran-linked groups like APT34, and this campaign follows that established pattern closely.​ Inside the Infection: DLL Sideloading and Persistent Access The infection mechanism in Attack Chain 1 was designed to blend into legitimate system activity without raising alarms. After SPLITDROP extracted its payload into a local directory, it launched a genuine VLC Media Player binary, which automatically sideloaded a malicious DLL named  libvlc.dll  placed in the same folder. This DLL sideloading technique exploits the trust that Windows places in recognized applications and does not require elevated privileges to run. The malicious DLL, named TWINTASK, functioned as a worker module that polled a local text file every 15 seconds, reading and executing Base64-encoded PowerShell commands received from the C2 orchestrator.​ Contents of the working directory after SPLITDROP extraction (Source – Zscaler) TWINTASK then launched WingetUI.exe, which sideloaded a second malicious DLL named hostfxr.dll — the component called TWINTALK. This acted as the C2 orchestrator, beaconing to remote servers at randomized intervals between 108 and 180 seconds to avoid pattern-based network detection rules. To verify that requests came from genuinely infected machines rather than automated scanners, TWINTALK generated dynamic URI paths with appended checksum values. The C2 server added verification through a hardcoded browser User-Agent string and applied geofencing to restrict responses to traffic from specific geographic regions only.​ Persistence was established through Windows Registry Run keys, ensuring both VLC.exe and WingetUI.exe relaunched automatically after every system restart, keeping the infection alive across reboots. GHOSTFORM took a more creative approach — it launched an invisible Windows form with near-zero opacity, hidden from the taskbar — to delay its own execution without calling any Windows API that could trigger behavioral analysis tools.​ Security teams should enforce strict application allowlisting to prevent unauthorized DLL sideloading through trusted binaries. Email and web gateways should be configured to block password-protected archives from unverified senders. Enabling PowerShell script block logging and monitoring Windows Registry Run keys for unexpected new entries are critical defensive steps against this type of intrusion. Network teams should flag outbound HTTPS traffic with randomized URI patterns and non-standard JWT authorization headers, as these behavioral indicators align with the C2 communication profile observed in this campaign. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs appeared first on Cyber Security News .
cybersecuritynews.com
March 4, 2026 at 3:48 PM
📢 Dust Specter (APT présumé lié à l’Iran) cible des officiels irakiens avec SPLITDROP/TWINTASK/TWINTALK et GHOSTF…📝 …
https://cyberveille.ch/posts/2026-03-08-dust-specter-apt-presume-lie-a-liran-cible-des-officiels-irakiens-avec-splitdrop-twintask-twintalk-et-ghostform/ #APT_lié_à_l_Iran #Cyberveil…
March 8, 2026 at 8:00 PM
Iran-nexus APT Dust Specter targets Iraq officials with new malware

A campaign by Iran-linked group Dust Specter is targeting Iraqi officials with phishing emails delivering new malware families. Zscaler ThreatLabz researchers linked the Iran-nexus group Dust Specter to a campaig…
#hackernews #news
Iran-nexus APT Dust Specter targets Iraq officials with new malware
A campaign by Iran-linked group Dust Specter is targeting Iraqi officials with phishing emails delivering new malware families. Zscaler ThreatLabz researchers linked the Iran-nexus group Dust Specter to a campaign targeting Iraqi government officials. Threat actors impersonated the country’s Ministry of Foreign Affairs in phishing messages that delivered previously unseen malware, including SPLITDROP, TWINTASK, TWINTALK, […]
securityaffairs.com
March 7, 2026 at 7:30 AM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware

A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country's Ministry of Foreign Affairs to deliver a set of never-before-s…
#hackernews #news
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country's Ministry of Foreign Affairs to deliver a set of never-before-seen malware. Zscaler ThreatLabz, which observed the activity in January 2026, is tracking the cluster under the name Dust Specter. The attacks, which manifest in the form of two different
thehackernews.com
March 6, 2026 at 9:54 AM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Thursday, March 5, 2026
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
Iran-linked Dust Specter targeted Iraqi officials using fake ministry lures and new malware families uncovered by Zscaler.
thehackernews.com
March 5, 2026 at 6:42 PM
Iran-linked 'Dust Specter' targets Iraqi officials with advanced malware SPLITDROP and GHOSTFORM. Stay vigilant against evolving cyber threats. #CyberSecurity #ThreatIntelligence #Malware Link: thedailytechfeed.com/iran-linked-...
March 7, 2026 at 6:11 AM
Iranian APT 'Dust Specter' targets Iraqi officials with AI-enhanced malware, introducing novel tools like SPLITDROP and GHOSTFORM. #CyberSecurity #APT #Malware #AI #Iraq Link: thedailytechfeed.com/iranian-apt-...
March 5, 2026 at 6:57 PM
Iran-linked threat actor Dust Specter targeted Iraqi government officials using spoofed Ministry of Foreign Affairs emails to deploy four new malware variants: SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
March 5, 2026 at 12:15 PM
イラン関連「Dust Specter」APTがAI支援マルウェアをイラク高官に展開

イラン系APTグループ「Dust Specter」は、AI支援カスタム.NETマルウェアを使用してイラク政府高官を標的にしており、DLLサイドローディング、インメモリPowerShell、ClickFixスタイルのルアーをブレンドした2つの攻撃チェーンを使用しています。 2026年1月、Zscaler ThreatLabzはイラク高官を標的とした新しいキャンペーンを追跡しました。このキャンペーンでは、攻撃者がイラク外務省になりすまし、侵害された政府インフラをペイロードのホスティングに悪用しました。…
イラン関連「Dust Specter」APTがAI支援マルウェアをイラク高官に展開
イラン系APTグループ「Dust Specter」は、AI支援カスタム.NETマルウェアを使用してイラク政府高官を標的にしており、DLLサイドローディング、インメモリPowerShell、ClickFixスタイルのルアーをブレンドした2つの攻撃チェーンを使用しています。 2026年1月、Zscaler ThreatLabzはイラク高官を標的とした新しいキャンペーンを追跡しました。このキャンペーンでは、攻撃者がイラク外務省になりすまし、侵害された政府インフラをペイロードのホスティングに悪用しました。 ThreatLabzは4つの未記載の.NETコンポーネント(SPLITDROP、TWINTASK、TWINTALK、GHOSTFORM)を特定しました。これらは2つの関連する攻撃チェーンで使用されています。 インフラの再利用により、このグループは2025年7月のClickFix作戦とも関連付けられます。この作戦では、ドメインmeetingapp[.]siteを経由してWebexテーマのルアーが兵器化されました。 ThreatLabzが内部的に命名した「Dust Specter」は、重複するツール、被害者プロフィール、およびAPT34にリンクされた作戦を含むイラク対象の過去のイラン系APT活動とのTTPに基づいて、中程度から高の信頼度でイラン系と評価されています。 SPLITDROP、TWINTASK、TWINTALK 最初の攻撃チェーンは、イラク外務省のコンテンツになりすましている「mofa‑Network‑code.rar」という名前のパスワード保護されたRARアーカイブで始まります。 内部には、WinRARになりすました32ビット.NETバイナリがSPLITDROPドロッパーとして機能し、ユーザーにパスワードの入力を求め、PBKDF2派生キーを使用して埋め込まれたAES-256暗号化リソースをC:\ProgramData\PolGuid.zipに復号化します。 アーカイブはPolGuidディレクトリに展開され、TWINTASK workerモジュールへのDLLサイドローディングに使用される正規のVLC.exeが含まれています。​ 悪意のあるlibvlc.dllを経由してロードされたTWINTASKは、C:\ProgramData\PolGuid\in.txtを15秒ごとにポーリングし、コマンドをbase64デコードし(先頭のジャンク文字をスキップ)、PowerShell経由で実行し、結果をout.txtに記録します。 初期コマンドは、VLC.exeとバンドルされたWingetUI.exeのRun-keyエントリを作成して永続性を確立し、これはTWINTALK C2オーケストレータであるhostfxr.dllをサイドロードします。​ TWINTALKはランダムに生成された16進URIパスと、サンドボックストラフィックから実ボットを区別するためのカスタム6文字チェックサムを使用してC2にビーコンを送信し、ボットIDとバージョンをAuthorizationヘッダーで送信される弱く署名されたHS256 JWTにラップします。 コマンド処理は意図的に最小限です。タイプ0はin.txt/out.txtチャネル経由でPowerShellを実行し、タイプ1はファイルをダウンロードし、タイプ2はローカルデータをアップロードします。JSON応答は位置的に解析され、キーベースの検出を回避します。 GHOSTFORM統合RAT 2番目の攻撃チェーンは、分割アーキテクチャをGHOSTFORM(SPLITDROP、TWINTASK、TWINTALKの機能を統合し、ステルスとソーシャルエンジニアリングにより力を入れた単一の.NET RAT)に置き換えます。 いくつかのサンプルには、政府職員向けの公式外務省アンケートであるかのような偽のアラビア語調査を開く、ハードコードされたGoogle Forms URLが埋め込まれています。 GHOSTFORMは引き続きジッター付きビーコン遅延を使用していますが、Windowsウェイト APIの代わりに、ほぼ透明な10×15のWindowsフォーム(不透明度がほぼゼロで、タスクバーから非表示)を生成し、メインループに戻る前に実行を遅延させるためにタイマーを使用します。 インフラとソーシャルエンジニアリングスタイルのこの再利用は、2025年7月のWebex作戦とDust Specterの2026年イラク焦点キャンペーン間の関連性をさらに強化しています。 また、単一インスタンスを強制するためにGlobal_ミューテックスを作成し、ランダム値の代わりにアセンブリ作成時刻からボットIDを派生させ、ランダムに生成されたように見えるゼロ以外のボットバージョン文字列を使用しています。​ ThreatLabzアナリストは、TWINTALK およびGHOSTFORMコード内の絵文字、異常なUnicode、プレースホルダーのようなマジック定数(たとえば、チェックサムルーチン内の0xABCDEF)に注目し、イラン関連の他のキャンペーンで生成AI作成スニペットと関連付けられているパターンと一致しています。 これは、攻撃者がAI支援マルウェア開発を試験していることを示唆しており、イラン系APTがツールとトレードクラフトにAIを統合しているというより広い報告と一致しています。 同じC2ドメイン「meetingapp[.]site」は、以前、WinWebex.exeペイロードをダウンロードして長寿命スケジュール済みタスクを登録するPowerShellコマンドをコピーペーストするよう被害者に指示するWebexテーマのClickFixルアーをホストしていました。 侵害の指標(IOC) ネットワーク指標 種類 指標 C2ドメイン lecturegenieltd[.]pro C2ドメイン meetingapp[.]site C2ドメイン afterworld[.]store C2ドメイン girlsbags[.]shop C2ドメイン onlinepettools[.]shop C2ドメイン web14[.]info C2ドメイン web27[.]info 攻撃チェーン2を含むZIPアーカイブをホストするURL hxxps://ca[.]iq/packages/mofaSurvey_20_30_oct.zip 翻訳元:
blackhatnews.tokyo
March 4, 2026 at 1:07 PM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by imperso...

Origin | Interest | Match
March 5, 2026 at 12:40 PM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware thehackernews.com/2026/03/dust...
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
Iran-linked Dust Specter targeted Iraqi officials using fake ministry lures and new malware families uncovered by Zscaler.
thehackernews.com
March 8, 2026 at 11:42 AM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware - CyberSecurity
Ravie LakshmananMar 05, 2026Malware / Threat Intelligence
cybersecurity.rozeepk.com
March 5, 2026 at 12:21 PM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware https://thehackernews.com/2026/03/dust-specter-targets-iraqi-officials.html
March 6, 2026 at 6:21 AM
イラク政府高官が標的、新マルウェアSPLITDROPとGHOSTFORMが確認(Zscaler)
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
Iran-linked Dust Specter targeted Iraqi officials using fake ministry lures and new malware families uncovered by Zscaler.
thehackernews.com
March 5, 2026 at 12:43 PM
Zscaler ThreatLabz reports Dust Specter APT activity in January 2026 targeting Iraqi government officials. Two attack chains deploy previously undocumented tools including SPLITDROP, TWINTASK, TWINTALK and the GHOSTFORM RAT. www.zscaler.com/blogs/securi...
March 4, 2026 at 9:34 AM
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
March 5, 2026 at 8:01 PM