Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

SPLITDROP

SPLITDROP is a previously undocumented 32-bit .NET dropper used in a January 2026 phishing campaign targeting Iraqi government officials. The activity was attributed with medium-to-high confidence by Zscaler ThreatLabz to Dust Specter, a suspected Iran-nexus threat actor, which impersonated Iraq’s Ministry of Foreign Affairs in social-engineering lures. SPLITDROP was delivered in a password-protected RAR archive, including mofa-Network-code.rar, and masqueraded as a WinRAR application. When executed, it decrypted an embedded payload using AES-256-CBC with PKCS7 padding and a PBKDF2-derived 256-bit key, then wrote and extracted a ZIP archive to C:\ProgramData\PolGuid. It displayed a fake error message ('The download did not complete successfully') while continuing execution. Its primary role was to deploy two additional modules, TWINTASK and TWINTALK, by launching legitimate software for DLL sideloading: VLC.exe sideloaded the malicious libvlc.dll (TWINTASK), and WingetUI.exe sideloaded the malicious hostfxr.dll (TWINTALK). Through this chain, the malware established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run values for VLC and WingetUI. TWINTASK polled C:\ProgramData\PolGuid\in.txt every 15 seconds for Base64-encoded PowerShell commands and wrote results to out.txt, while TWINTALK acted as the command-and-control orchestrator, using randomized beacon delays, custom URI paths, and JWT-based communications to support script execution and file transfer. High-confidence associated artifacts include the paths C:\ProgramData\PolGuid.zip, C:\ProgramData\PolGuid, C:\ProgramData\PolGuid\in.txt, and C:\ProgramData\PolGuid\out.txt; the dropped modules TWINTASK and TWINTALK; and the related C2 domain meetingapp[.]site observed in Dust Specter activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Dust Specter

Analysis confirmed four novel malware families: SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. SPLITDROP is a 32-bit .NET dropper that decrypts an AES-256 CBC embedded payload using PBKDF2 key derivation.

via centripetal threat researchcentripetal.ai
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence2

"Threat actors impersonated the country’s Ministry of Foreign Affairs in phishing messages that delivered previously unseen malware..."

T1566.001Spearphishing AttachmentEvidence1

"involved a password-protected RAR archive with the WinRAR app-spoofing .NET binary"

Execution

3 techniques
T1059Command and Scripting InterpreterEvidence1

"...new malware such as SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM."; "...TernDoor Windows backdoor, and the PeerTime P2P Linux backdoor."; "...Python-based backdoor named AnonDoor."

T1204User ExecutionEvidence4

"Attack Chain 1 begins with a password-protected archive containing a dropper named SPLITDROP... Once executed, it decrypts and deploys two modules..."

T1574.001DLLEvidence1

"...uses DLL sideloading with legitimate software such as VLC and WingetUI."

Persistence

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence2

Attack Chain 1 used SPLITDROP, a .NET dropper delivering TWINTASK and TWINTALK via DLL sideloading into legitimate VLC.exe and WingetUI.exe processes, establishing file-based command polling through in.txt and out.txt with persistence via Windows Run registry keys.

Privilege Escalation

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence2

Attack Chain 1 used SPLITDROP, a .NET dropper delivering TWINTASK and TWINTALK via DLL sideloading into legitimate VLC.exe and WingetUI.exe processes, establishing file-based command polling through in.txt and out.txt with persistence via Windows Run registry keys.

Stealth

4 techniques
T1036MasqueradingEvidence3

"...a dropper named SPLITDROP, disguised as a WinRAR application."

T1140Deobfuscate/Decode Files or InformationEvidence2

“decrypted an embedded payload using AES-256 encryption and dropped malicious files…”

T1574.001DLLEvidence1

"...uses DLL sideloading with legitimate software such as VLC and WingetUI."

T1612Build Image on HostEvidence1

“The C2 server also utilized geofencing techniques and User-Agent verification.”

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

"SplitDrop ... enabled the deployment of the TwinTask and TwinTalk DLL files"

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.