#twintalk
The more ya know - Don't ask what it tasted like, all I remember is burning.
#pngtuber #twitch #pokemon #japan #funfacts #twintalk
October 31, 2024 at 2:17 AM
Stephanie Sidley of YouTube's The Sidley Twins/TwinTalk has released a book through Amazon about a special needs dog. All proceeds from the book goes to animal charities.
www.amazon.com/Really-Speci...
My Really Special, Super Terrific, One-of-a-Kind Dog
My Really Special, Super Terrific, One-of-a-Kind Dog [Rick Kunkler, Stephanie Sidley &] on Amazon.com. *FREE* shipping on qualifying offers. My Really Special, Super Terrific, One-of-a-Kind Dog
www.amazon.com
May 4, 2025 at 7:57 PM

Day24 : 'Fraternally Yours!' A tribute to the unique bond of fraternal twins. What do you love most about twin friendships? thirtypaintingsinthirtydays #BeingHuman #FraternallyYours #twintalk #caricatureart #familyconnection
Watch reel here
www.instagram.com/reel/DFOW6l1...
January 24, 2025 at 10:17 PM
~Recordedfuture~
AI accelerated Iran's cyber, influence, and surveillance operations as a force multiplier across hybrid warfare domains without creating fundamentally new capabilities.
-
IOCs: CHAR, MiniFast, TWINTALK
-
#AI #APT #Iran #ThreatIntel
AI Enhanced Iran's Asymmetric Warfare in 2026
www.recordedfuture.com
July 16, 2026 at 1:30 PM
Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs
Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs
In January 2026, a targeted cyberattack emerged against government officials in Iraq. The threat group, tracked as Dust Specter, impersonated Iraq’s Ministry of Foreign Affairs to trick high-value targets into downloading malicious files. The campaign introduced four previously undocumented malware tools — SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM — each reflecting the precision of a seasoned, state-linked actor. Researchers attribute this campaign with medium-to-high confidence to an Iran-nexus threat actor, based on consistent overlaps in tools, techniques, and victim selection with known Iranian APT groups.​ Dust Specter’s first attack chain was delivered through a password-protected RAR archive named mofa-Network-code.rar, disguised as an official Ministry document. When opened, a .NET binary masquerading as a WinRAR application — SPLITDROP — decrypted an embedded payload using AES-256 encryption and dropped malicious files onto the victim’s machine. SPLITDROP displayed a false error message ,  “The download did not complete successfully,”  while operating silently. The second chain used GHOSTFORM, which opened a fake Arabic Google Form survey posing as a government questionnaire while malware ran undetected.​ Google Form Lure (Source – Zscaler) Zscaler ThreatLabz researchers identified fingerprints in the codebase pointing to the use of generative AI during malware development. Emojis and unicode characters embedded inside both TWINTALK and GHOSTFORM source code match a pattern tied to AI-generated programming. A hardcoded seed value of 0xABCDEF — a placeholder found in AI-written code — was also uncovered inside TWINTALK’s checksum generation function. This marks a shift in how threat actors approach development, with AI now used not just for planning but for writing functional malicious code.​ The same group was also connected to a ClickFix-style attack from July 2025, where a webpage mimicking a Cisco Webex Government meeting invitation directed victims to run a PowerShell command. ClickFix Lure (Source – Zscaler) That command downloaded a malicious binary and registered a scheduled task to execute every two hours. Iraq’s Ministry of Foreign Affairs has historically been a priority target for Iran-linked groups like APT34, and this campaign follows that established pattern closely.​ Inside the Infection: DLL Sideloading and Persistent Access The infection mechanism in Attack Chain 1 was designed to blend into legitimate system activity without raising alarms. After SPLITDROP extracted its payload into a local directory, it launched a genuine VLC Media Player binary, which automatically sideloaded a malicious DLL named  libvlc.dll  placed in the same folder. This DLL sideloading technique exploits the trust that Windows places in recognized applications and does not require elevated privileges to run. The malicious DLL, named TWINTASK, functioned as a worker module that polled a local text file every 15 seconds, reading and executing Base64-encoded PowerShell commands received from the C2 orchestrator.​ Contents of the working directory after SPLITDROP extraction (Source – Zscaler) TWINTASK then launched WingetUI.exe, which sideloaded a second malicious DLL named hostfxr.dll — the component called TWINTALK. This acted as the C2 orchestrator, beaconing to remote servers at randomized intervals between 108 and 180 seconds to avoid pattern-based network detection rules. To verify that requests came from genuinely infected machines rather than automated scanners, TWINTALK generated dynamic URI paths with appended checksum values. The C2 server added verification through a hardcoded browser User-Agent string and applied geofencing to restrict responses to traffic from specific geographic regions only.​ Persistence was established through Windows Registry Run keys, ensuring both VLC.exe and WingetUI.exe relaunched automatically after every system restart, keeping the infection alive across reboots. GHOSTFORM took a more creative approach — it launched an invisible Windows form with near-zero opacity, hidden from the taskbar — to delay its own execution without calling any Windows API that could trigger behavioral analysis tools.​ Security teams should enforce strict application allowlisting to prevent unauthorized DLL sideloading through trusted binaries. Email and web gateways should be configured to block password-protected archives from unverified senders. Enabling PowerShell script block logging and monitoring Windows Registry Run keys for unexpected new entries are critical defensive steps against this type of intrusion. Network teams should flag outbound HTTPS traffic with randomized URI patterns and non-standard JWT authorization headers, as these behavioral indicators align with the C2 communication profile observed in this campaign. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Iran‑Nexus APT ‘Dust Specter’ Hits Iraqi Officials with AI‑Assisted Malware and Novel RATs appeared first on Cyber Security News .
cybersecuritynews.com
March 4, 2026 at 3:48 PM
📢 Dust Specter (APT présumé lié à l’Iran) cible des officiels irakiens avec SPLITDROP/TWINTASK/TWINTALK et GHOSTF…📝 …
https://cyberveille.ch/posts/2026-03-08-dust-specter-apt-presume-lie-a-liran-cible-des-officiels-irakiens-avec-splitdrop-twintask-twintalk-et-ghostform/ #APT_lié_à_l_Iran #Cyberveil…
March 8, 2026 at 8:00 PM
Iran-nexus APT Dust Specter targets Iraq officials with new malware

A campaign by Iran-linked group Dust Specter is targeting Iraqi officials with phishing emails delivering new malware families. Zscaler ThreatLabz researchers linked the Iran-nexus group Dust Specter to a campaig…
#hackernews #news
Iran-nexus APT Dust Specter targets Iraq officials with new malware
A campaign by Iran-linked group Dust Specter is targeting Iraqi officials with phishing emails delivering new malware families. Zscaler ThreatLabz researchers linked the Iran-nexus group Dust Specter to a campaign targeting Iraqi government officials. Threat actors impersonated the country’s Ministry of Foreign Affairs in phishing messages that delivered previously unseen malware, including SPLITDROP, TWINTASK, TWINTALK, […]
securityaffairs.com
March 7, 2026 at 7:30 AM
Iran-linked threat actor Dust Specter targeted Iraqi government officials using spoofed Ministry of Foreign Affairs emails to deploy four new malware variants: SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
March 5, 2026 at 12:15 PM
イラン関連「Dust Specter」APTがAI支援マルウェアをイラク高官に展開

イラン系APTグループ「Dust Specter」は、AI支援カスタム.NETマルウェアを使用してイラク政府高官を標的にしており、DLLサイドローディング、インメモリPowerShell、ClickFixスタイルのルアーをブレンドした2つの攻撃チェーンを使用しています。 2026年1月、Zscaler ThreatLabzはイラク高官を標的とした新しいキャンペーンを追跡しました。このキャンペーンでは、攻撃者がイラク外務省になりすまし、侵害された政府インフラをペイロードのホスティングに悪用しました。…
イラン関連「Dust Specter」APTがAI支援マルウェアをイラク高官に展開
イラン系APTグループ「Dust Specter」は、AI支援カスタム.NETマルウェアを使用してイラク政府高官を標的にしており、DLLサイドローディング、インメモリPowerShell、ClickFixスタイルのルアーをブレンドした2つの攻撃チェーンを使用しています。 2026年1月、Zscaler ThreatLabzはイラク高官を標的とした新しいキャンペーンを追跡しました。このキャンペーンでは、攻撃者がイラク外務省になりすまし、侵害された政府インフラをペイロードのホスティングに悪用しました。 ThreatLabzは4つの未記載の.NETコンポーネント(SPLITDROP、TWINTASK、TWINTALK、GHOSTFORM)を特定しました。これらは2つの関連する攻撃チェーンで使用されています。 インフラの再利用により、このグループは2025年7月のClickFix作戦とも関連付けられます。この作戦では、ドメインmeetingapp[.]siteを経由してWebexテーマのルアーが兵器化されました。 ThreatLabzが内部的に命名した「Dust Specter」は、重複するツール、被害者プロフィール、およびAPT34にリンクされた作戦を含むイラク対象の過去のイラン系APT活動とのTTPに基づいて、中程度から高の信頼度でイラン系と評価されています。 SPLITDROP、TWINTASK、TWINTALK 最初の攻撃チェーンは、イラク外務省のコンテンツになりすましている「mofa‑Network‑code.rar」という名前のパスワード保護されたRARアーカイブで始まります。 内部には、WinRARになりすました32ビット.NETバイナリがSPLITDROPドロッパーとして機能し、ユーザーにパスワードの入力を求め、PBKDF2派生キーを使用して埋め込まれたAES-256暗号化リソースをC:\ProgramData\PolGuid.zipに復号化します。 アーカイブはPolGuidディレクトリに展開され、TWINTASK workerモジュールへのDLLサイドローディングに使用される正規のVLC.exeが含まれています。​ 悪意のあるlibvlc.dllを経由してロードされたTWINTASKは、C:\ProgramData\PolGuid\in.txtを15秒ごとにポーリングし、コマンドをbase64デコードし(先頭のジャンク文字をスキップ)、PowerShell経由で実行し、結果をout.txtに記録します。 初期コマンドは、VLC.exeとバンドルされたWingetUI.exeのRun-keyエントリを作成して永続性を確立し、これはTWINTALK C2オーケストレータであるhostfxr.dllをサイドロードします。​ TWINTALKはランダムに生成された16進URIパスと、サンドボックストラフィックから実ボットを区別するためのカスタム6文字チェックサムを使用してC2にビーコンを送信し、ボットIDとバージョンをAuthorizationヘッダーで送信される弱く署名されたHS256 JWTにラップします。 コマンド処理は意図的に最小限です。タイプ0はin.txt/out.txtチャネル経由でPowerShellを実行し、タイプ1はファイルをダウンロードし、タイプ2はローカルデータをアップロードします。JSON応答は位置的に解析され、キーベースの検出を回避します。 GHOSTFORM統合RAT 2番目の攻撃チェーンは、分割アーキテクチャをGHOSTFORM(SPLITDROP、TWINTASK、TWINTALKの機能を統合し、ステルスとソーシャルエンジニアリングにより力を入れた単一の.NET RAT)に置き換えます。 いくつかのサンプルには、政府職員向けの公式外務省アンケートであるかのような偽のアラビア語調査を開く、ハードコードされたGoogle Forms URLが埋め込まれています。 GHOSTFORMは引き続きジッター付きビーコン遅延を使用していますが、Windowsウェイト APIの代わりに、ほぼ透明な10×15のWindowsフォーム(不透明度がほぼゼロで、タスクバーから非表示)を生成し、メインループに戻る前に実行を遅延させるためにタイマーを使用します。 インフラとソーシャルエンジニアリングスタイルのこの再利用は、2025年7月のWebex作戦とDust Specterの2026年イラク焦点キャンペーン間の関連性をさらに強化しています。 また、単一インスタンスを強制するためにGlobal_ミューテックスを作成し、ランダム値の代わりにアセンブリ作成時刻からボットIDを派生させ、ランダムに生成されたように見えるゼロ以外のボットバージョン文字列を使用しています。​ ThreatLabzアナリストは、TWINTALK およびGHOSTFORMコード内の絵文字、異常なUnicode、プレースホルダーのようなマジック定数(たとえば、チェックサムルーチン内の0xABCDEF)に注目し、イラン関連の他のキャンペーンで生成AI作成スニペットと関連付けられているパターンと一致しています。 これは、攻撃者がAI支援マルウェア開発を試験していることを示唆しており、イラン系APTがツールとトレードクラフトにAIを統合しているというより広い報告と一致しています。 同じC2ドメイン「meetingapp[.]site」は、以前、WinWebex.exeペイロードをダウンロードして長寿命スケジュール済みタスクを登録するPowerShellコマンドをコピーペーストするよう被害者に指示するWebexテーマのClickFixルアーをホストしていました。 侵害の指標(IOC) ネットワーク指標 種類 指標 C2ドメイン lecturegenieltd[.]pro C2ドメイン meetingapp[.]site C2ドメイン afterworld[.]store C2ドメイン girlsbags[.]shop C2ドメイン onlinepettools[.]shop C2ドメイン web14[.]info C2ドメイン web27[.]info 攻撃チェーン2を含むZIPアーカイブをホストするURL hxxps://ca[.]iq/packages/mofaSurvey_20_30_oct.zip 翻訳元:
blackhatnews.tokyo
March 4, 2026 at 1:07 PM
AI駆動型キャンペーンでイラク政府高官を標的とするイラン系サイバー脅威アクター

イラン系のサイバー脅威アクターが、AIツールを使用してイラク外務省になりすまし、イラクの政府高官を標的にしている。 イラク内の政府関連インフラが侵害され、このキャンペーンの一部として配布される悪意あるペイロードをホストするために使用された。 このキャンペーンは2026年1月にZscaler ThreatLabzによって検出され、脅威アクターをDust Specterとして追跡しており、「中程度から高い信頼度で」イランに帰属させている。…
AI駆動型キャンペーンでイラク政府高官を標的とするイラン系サイバー脅威アクター
イラン系のサイバー脅威アクターが、AIツールを使用してイラク外務省になりすまし、イラクの政府高官を標的にしている。 イラク内の政府関連インフラが侵害され、このキャンペーンの一部として配布される悪意あるペイロードをホストするために使用された。 このキャンペーンは2026年1月にZscaler ThreatLabzによって検出され、脅威アクターをDust Specterとして追跡しており、「中程度から高い信頼度で」イランに帰属させている。 ThreatLabzは、このキャンペーンで以前未文書化のマルウェアの使用を発見し、Split Drop、TwinTask、TwinTalk、GhostFormが含まれる。 研究者らはまた、Dust Specterが生成AIをマルウェア開発に活用していることを示すコードベース内のいくつかのフィンガープリントを観察した。 Dust Specterの2026年1月攻撃キャンペーンの説明 悪意あるキャンペーンは2つの異なる攻撃チェーンに従って展開されている。 最初の攻撃チェーンは、mofa-Network-code.rarという名前のパスワード保護されたRARアーカイブの配信を含む。このアーカイブ内に存在する32ビットの.NETバイナリはWinRARアプリケーションに偽装され、エンドポイント上の攻撃チェーンを開始する。ThreatLabzはこのバイナリをSplitDropと呼んだ。 このバイナリはTwinTaskとTwinTalkの2つの悪意あるダイナミックリンクライブラリ(DLL)ファイルのドロッパーとして機能する。 TwinTaskの主な目的は、実行可能な新しいコマンドのファイルをポーリングし、PowerShellを使用してそれらを実行して、ターゲット環境での永続性を確保することである。 TwinTalkはコマンド・アンド・コントロール(C2)オーケストレーターとして機能し、その主な目的はC2サーバから新しいコマンドをポーリングし、ワーカーモジュールと調整し、コマンド実行の結果を流出させることである。 TwinTaskとTwinTalkは、コード実行に使用されるファイルベースのポーリングメカニズムを実装するために並行して動作する。 3月2日に発表された、このキャンペーンについてのレポートで、ThreatLabzの研究者らはTwinTalk C2ドメインが2025年7月にDust Specterによってシスコウェブエックス会議招待を装ったウェブページをホストするために使用されたと述べた。 ウェブページは正規のシスコウェブエックスソフトウェアをダウンロードするためのリンクを含み、被害者に「ウェブエックス・フォー・ガバメント」オプションを選択するよう促し、被害者に会議IDを取得するための指示に従うよう誘導した。 これらの指示は、脅威アクターがソーシャルエンジニアリングを実装するために採用する典型的な方法であり、ClickFixスタイルの攻撃を実装する。 2番目の攻撃チェーンは、最初の攻撃チェーンのすべての機能を単一のバイナリに統合している。 ソーシャルエンジニアリングルアーとしてGoogle Formsを使用し、メモリ内PowerShellスクリプト実行を使用してC2サーバから受信したコマンドを実行し、ファイルシステムのフットプリントを削減する。 最初の攻撃チェーンとは異なり、脅威アクターはこの場合DLLサイドローディングを伴う分割アーキテクチャを使用しない。代わりに、ThreatLabzによってGhostFormと呼ばれる.NETベースのリモートアクセストロイの木馬(RAT)を使用し、最初の攻撃チェーンのすべての機能を1つのバイナリに統合し、メモリ内PowerShellスクリプト実行を使用する。 ThreatLabzは、TwinTalkとGhostFormをデコンパイルするときに、コードベース内での絵文字とユニコードテキストの使用を特定した。 「このユニークなコーディングスタイルは、マルウェア開発中に生成AIツールが使用された可能性が高く、他のキャンペーンで文書化されたトレンドである」と彼らは書いた。 翻訳元:
blackhatnews.tokyo
March 3, 2026 at 10:53 AM
Zscaler ThreatLabz reports Dust Specter APT activity in January 2026 targeting Iraqi government officials. Two attack chains deploy previously undocumented tools including SPLITDROP, TWINTASK, TWINTALK and the GHOSTFORM RAT. www.zscaler.com/blogs/securi...
March 4, 2026 at 9:34 AM
Happy Sunday All,

If you're looking for a great baseball podcast to listen to then give my friends @TwinTalkyanks pod a listen. Their latest episode, Let Them Fight! is on Spotify & #SoundCloud

soundcloud.com/twintalkyanks/…
Let Them Fight! by TwinTalkYanks
On this weeks episode TwinTalk talks about the recent news of James Paxton going down, spring training battles we are going to see and we answer questions given to us by you guys! Make sure to follow us on Twitter and Instagram: @TwinTalkYanks
soundcloud.com
March 5, 2025 at 6:55 PM
~Zscaler~
Suspected Iran-nexus APT 'Dust Specter' targets Iraqi government officials with new custom malware like GHOSTFORM and TWINTALK.
-
IOCs: meetingapp[. ]site, ca. iq
-
#APT #DustSpecter #Malware #ThreatIntel
Dust Specter APT Targets Iraqi Gov't Officials
www.zscaler.com
March 2, 2026 at 5:07 PM