Researchers at Acronis reported a cyberespionage campaign—tracked as CrescentHarvest—targeting Farsi-speaking individuals sympathetic to Iran’s anti-government protests, including potential dissidents and supporters abroad. The operation uses social engineering lures packaged as malicious archive files containing authentic-looking protest media and a Farsi-language report that portrays the protests positively and repeats protest slogans, likely exploiting heightened demand for information amid Iranian internet blackouts.
The archive includes files disguised as a video and an image that deploy a previously undocumented malware family dubbed CRESCENTHARVEST, assessed to function as both a remote access trojan and information stealer. Reported capabilities include command execution, keystroke logging, and theft of sensitive data such as saved credentials, browser history/cookies, and Telegram account information, along with checks for installed antivirus to modulate behavior. While no specific APT group was named, Acronis assessed the code, infrastructure, and victimology as consistent with an Iran-aligned actor; reporting also noted operational quirks (e.g., unused C2 endpoints and buggy User-Agent handling) that may indicate lower maturity or a rapidly assembled campaign tied to the protest-driven geopolitical moment.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
In its disclosure, Acronis said code, infrastructure, and scripting similarities overlapped with activity previously described by Check Point and associated with Educated Manticore, a cluster overlapping APT42/Charming Kitten/Mint Sandstorm. Acronis emphasized that this was only a low-confidence, non-definitive attribution.
On February 17, 2026, Acronis Threat Research Unit published findings on the previously undocumented CRESCENTHARVEST malware campaign targeting Farsi-speaking protesters, dissidents, and supporters of Iran's anti-government movement. The company assessed the activity as likely aligned with Iranian state interests, though it stopped short of firm attribution.
Victims who opened the disguised shortcut files triggered a PowerShell-based infection chain that established persistence and used Google-signed software_reporter_tool.exe to sideload malicious DLLs. The malware functioned as both a RAT and information stealer, targeting browser credentials, cookies, Telegram data, and keystrokes.
On or shortly after January 9, 2026, attackers began distributing Farsi-language protest-themed archives containing decoy media and malicious LNK files. At least one bait image was dated January 9, indicating the operation was active by then.
A violent crackdown began on January 8, 2026, and internet blackouts hindered reporting inside Iran. The disruption likely increased demand for protest-related updates and created favorable conditions for social-engineering lures.
Protests spread across Iran in late December 2025, creating the political context later used as bait in a cyberespionage campaign. Subsequent reporting tied the malware lures directly to these demonstrations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceacronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.