TWINTALK
-
Suspected Iran-nexus actor impersonated Iraqi ministry to deploy novel malware
Zscaler ThreatLabz observed a January 2026 campaign that impersonated Iraq’s Ministry of Foreign Affairs to deliver SPLITDROP, TWINTASK, TWINTALK and GHOSTFORM using staged payloads, evasion and fileless execution.

