logo

CRESCENTHARVEST: Iranian protestors and dissidents targeted in cyberespionage campaign

ID: 54d8c525-bdc5-5f39-9c37-9f2224fdfc7f

STIX ID: report--54d8c525-bdc5-5f39-9c37-9f2224fdfc7f

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2026-02-17

Date Updated: 2026-07-24

...
...

**Executive Summary:** Acronis TRU identified a targeted espionage campaign dubbed CRESCENTHARVEST that lures Farsi-speaking individuals with protest-themed archives containing malicious .LNK shortcuts; the attack uses DLL sideloading of a signed Google binary to deploy two implants — one that decrypts Chrome app-bound keys and another that functions as a RAT/infostealer (keylogger, browser credential and Telegram data theft) — communicating with a C2 at servicelog-information.com (185.242.105.230); the report provides technical analysis, IoCs and notes probable Iranian-aligned motives with recommended defensive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.