Cyber Security News

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

A sophisticated new malware campaign named ‘CRESCENTHARVEST’ has surfaced, strategically exploiting the geopolitical unrest in Iran to target dissidents and protest supporters.

This cyberespionage operation leverages social engineering to deploy a dual-purpose threat capability, functioning as both a remote access trojan (RAT) and an advanced information stealer.

The attackers aim to compromise specific targets by mimicking legitimate protest-related content, thereby gaining trust and access to sensitive systems.

The infection chain begins with an archive file containing seemingly authentic media and reports about the ongoing protests.

Inside this package, victims encounter malicious .LNK files disguised as video or image files, such as VID_20260114_000556_609.mp4.lnk.

Once executed, these shortcuts trigger a hidden sequence that deploys the payload while simultaneously displaying the expected decoy content to avoid suspicion.

Attack chain (Source – Acronis)

This method effectively bypasses initial scrutiny by blending malicious indicators with genuine Farsi-language documents.

Acronis analysts identified that the malware employs a technique known as DLL sideloading, utilizing a signed Google executable, software_reporter_tool.exe, to load malicious libraries.

DLL sideloading (Source – Acronis)

This allows the threat actors to execute commands, capture keystrokes, and exfiltrate critical data like browser credentials and Telegram session files.

The files sent to the victim include a report and media files depicting the ongoing protests in Iran (Source – Acronis)

The campaign’s primary objective appears to be long-term surveillance and intelligence gathering on individuals sympathetic to the opposition movement

The operational sophistication suggests a well-resourced adversary, likely aligned with Iranian state interests.

By embedding the malware within a context that resonates emotionally with the target audience, the attackers increase the likelihood of successful infection.

The malware’s modular design enables it to adapt to different environments, ensuring that it can harvest extensive data while maintaining a low profile on the victim’s machine.

Bypassing App-Bound Encryption

A distinct technical feature of CRESCENTHARVEST is its specific module designed to evade Chrome’s App-Bound Encryption.

The malicious DLL, identified as urtcbased140d_d.dll, functions as a specialized implant that interacts directly with the browser’s internal COM interfaces to facilitate theft.

Instead of merely copying files, it constructs a browser context structure to legitimately request decryption services from the operating system, bypassing standard protection mechanisms.

Attack flow from an Iranian-affiliated campaign (Source – Acronis)

The module locates the Local State file within the user’s AppData directory to extract the encrypted key.

It then utilizes the CoCreateInstance function to instantiate an elevated COM broker, effectively tricking the system into decrypting the key.

Once decrypted, this sensitive information is exfiltrated via a named pipe to the main backdoor module, allowing the attackers to unlock and steal saved login credentials, cookies, and history.

To mitigate such threats, experts recommend that users employ hardware security keys and exercise extreme caution with unsolicited files.

Organizations should monitor for unusual COM object instantiations and strictly validate signed binaries to detect this evasion technique effectively.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

7 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

11 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

23 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

33 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago