Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
2026-03-05T13:24:17Z•69b4d4207430731d2bce7d8b9776fb53baa78e252ad5665a0cc01a8d067c0e5b
CVE-2026-0628CVE-2026-21385CVE-2026-21513CVE-2026-22719APT28APT41BadPawChrome CVE-2026-0628 (WebView) patching/privilege escalationCobalt StrikeCorunaCryptoWatersDust SpecterFreePBX web shellsGHOSTFORMGoogle/Qualcomm Android vulnerabilityHavocMFA bypassMeowMeowOAuth redirect abusePackagist malicious packagesRekoobeSPLITDROPSilver DragonStarkillerTycoon 2FAVMware Aria OperationsiOS exploit kitmalicious Go modulenpm supply-chain
What happened
A broad cluster of high-impact cyber activity and vulnerabilities was reported, combining state-linked espionage, supply-chain compromises, large-scale phishing/PhaaS operations, and actively exploited product flaws. Notable campaigns include Dust Specter (new SPLITDROP and GHOSTFORM) targeting Iraqi officials, APT28 operations deploying BadPaw/MeowMeow in Ukraine, and an APT41-linked Silver Dragon using Cobalt Strike and cloud-based C2. Multiple supply-chain and package-repo compromises were observed (malicious Packagist, npm and Go modules delivering cross-platform RATs/backdoors), alongside
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 69b4d4207430731d2bce7d8b9776fb53baa78e252ad5665a0cc01a8d067c0e5b
- Enrichment time
- 2026-03-05T13:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.