logo

CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware

ID: 439d8f19-90f9-54fb-b236-cbe5e8b64bde

STIX ID: report--439d8f19-90f9-54fb-b236-cbe5e8b64bde

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**CRESCENTHARVEST** is a targeted cyber-espionage campaign, likely Iran-aligned, that uses spear-phishing with double-extension LNK files and a malicious RAR/ZIP chain to sideload rogue DLLs via a Google-signed binary; the payload functions as a RAT and information stealer capable of keylogging, harvesting browser credentials/cookies, Telegram session data, enumerating accounts, and communicating with a C2 at servicelog-information.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.