CRESCENTHARVEST — Iranian IRGC-Aligned Cyberespionage Campaign Targeting Protestors & Dissidents via DLL Sideloading with Signed Google Executable
CRESCENTHARVEST (TL-2026-0159) is a high-severity advanced persistent threat campaign, first published 2026-02-28. It carries a reported Iran nexus and is not formally attributed, maps to 31 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-0159
- Threat ID
- TL-2026-0159
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-02-28
- Last reviewed
- 2026-02-28
- Attribution confidence
- NONE
- Nation-state nexus
- Iran
- Detection rules
- 9
- Indicators of compromise
- 23
Acronis Threat Research Unit (TRU) uncovered CRESCENTHARVEST, a cyberespionage campaign targeting supporters of Iran's ongoing protests. The attack delivers a dual-module malware payload — a RAT and infostealer — via DLL sideloading using a signed Google Chrome Software Reporter Tool executable, with initial access through malicious .LNK files disguised as protest-related media bundled in RAR archives.
How CRESCENTHARVEST works
CRESCENTHARVEST is a targeted cyberespionage campaign discovered by Acronis TRU in early 2026, designed to surveil and compromise Farsi-speaking Iranians sympathetic to the ongoing anti-IRGC protests. The campaign leverages geopolitical developments to deliver malware through social engineering, bundling malicious .LNK files alongside authentic protest images, videos, and a Farsi-language report titled 'the rebellious cities of Iran.'
The infection chain begins with spear-phishing or protracted social engineering, delivering a RAR archive containing decoy media and two malicious .LNK shortcuts disguised as video and image files. When clicked, the .LNK files invoke nested conhost.exe processes with --headless switches to obscure execution, spawning cmd.exe then PowerShell to extract a ZIP payload embedded within the .LNK to the user's %TEMP% folder.
Persistence is established through a novel scheduled task mechanism: instead of traditional startup triggers, the task fires on Windows NetworkProfile EventID 10000, executing the payload whenever the system establishes network connectivity — including after reboot or offline-to-online transitions.
The payload uses DLL sideloading via software_reporter_tool.exe, a legitimate Google-signed binary (Chrome's deprecated Software Reporter Tool, removed in 2023). The executable loads two malicious DLLs using LoadLibraryExA without path restrictions, enabling search order hijacking.
Module 1 (urtcbased140d_d.dll) is a C++ implant that bypasses Chrome's app-bound encryption by instantiating the browser's COM elevation broker (IElevator interface) to decrypt the master key from the Local State file. The decrypted key is saved to APPDATA\decrypted_appbound_key.txt and shared with Module 2 via a named pipe. This module shows heavy code overlap with the open-source ChromElevator project. PDB path artifact: E:\new\stealer\Stealer\x64\Release.
Module 2 (version.dll) is the main RAT/infostealer with extensive capabilities: keylogging via WH_KEYBOARD_LL hooks (logging to C:\Windows\System32\spool\Drivers\color\daT.txt), browser credential harvesting (Chrome, Firefox, Edge), Telegram Desktop session theft, user enumeration, shell command execution, directory traversal, DLL loading, WMI-based security product detection, and system profiling. It uses PEB walking to resolve APIs dynamically and XOR decryption with key '!@#$6756' for string obfuscation. Anti-analysis employs Windows Job Objects to restrict process memory ('Process on a Diet' technique).
C2 communications use JSON over HTTPS via WinHTTP APIs. The implant registers with {"Identifier":"admin"} and receives commands like KeyLog, Tel_s, F_log, Cook, GetUser, shell. A notable bug causes the malware to send the C2 domain as its User-Agent instead of the intended Chrome UA string, reducing evasion effectiveness. Multiple predefined C2 endpoints (/register_agent, /info, /Out, /upload, etc.) exist but most operations route through /Out and /upload.
Infrastructure centers on servicelog-information[.]com resolving to 185.242.105.230 hosted in Riga, Latvia on ASN AS42532 (VEESP-LV-AS), with historical Cloudflare CDN proxying via AS13335. The code shows methodological similarities to campaigns attributed to Iranian threat groups documented by Check Point Research (Educated Manticore, Nimbus Manticore), including similar LNK unpacking scripts, JSON-based C2 communication, and WinHTTP exfiltration patterns.
MITRE ATT&CK techniques used in TL-2026-0159
collection
T1005 Data from Local System; T1056.001 Keylogging; T1560 Archive Collected Data
stealth
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL; T1622 Debugger Evasion
exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File
discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.001 Local Account; T1518.001 Security Software Discovery
command-and-control
T1071.001 Web Protocols; T1132.001 Standard Encoding; T1573.002 Asymmetric Cryptography
credential-access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
privilege-escalation
T1546 Event Triggered Execution
initial-access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
resource-development
T1583.003 Virtual Private Server; T1587.001 Malware; T1588.002 Tool
Timeline of CRESCENTHARVEST
- Google deprecates and removes Software Reporter Tool (software_reporter_tool.exe) from Chrome, the binary later abused in this campaign for DLL sideloading.
- The Google code-signing certificate on software_reporter_tool.exe expires in 2024, but the binary remains signed and usable for sideloading.
- Threat actor prepares Farsi-language protest report ('the rebellious cities of Iran') and bundles authentic protest media with malicious .LNK files in RAR archives.
- Earliest protest images used in CRESCENTHARVEST decoy materials dated to January 9, 2026, establishing the campaign's minimum start date.
- C2 domain servicelog-information[.]com observed active, resolving to 185.242.105.230 (VEESP-LV-AS, Latvia) with intermittent Cloudflare CDN proxying.
- Acronis TRU begins actively monitoring the CRESCENTHARVEST campaign after discovering malware samples and bundled decoy files.
- Acronis TRU publishes full technical analysis of CRESCENTHARVEST campaign including IOCs, attack chain, and attribution analysis. Source: https://www.acronis.com/en/tru/posts/crescentharvest-iranian-protestors-and-dissidents-targeted-in-cyberespionage-campaign/
- Threadlinqs Intelligence publishes TL-2026-0159 with full MITRE mapping, IOCs, detections, and simulation coverage.
- As of 2026-05-29, CRESCENTHARVEST remains ACTIVE: the Acronis TRU report and corroborating coverage (Hacker News, The Record) describe an ongoing Iranian IRGC-aligned campaign with no reported takedown, sinkhole, or disruption of C2 servicelog-information[.]com (Latvia VEESP). With no CVE to patch, no successor, and IRGC dissident-surveillance and Manticore APT activity escalating Feb-May 2026, the threat persists.
Sources cited for CRESCENTHARVEST
- Acronis TRU: CRESCENTHARVEST — Iranian Protestors and Dissidents Targeted in Cyberespionage Campaign
- Check Point Research: Educated Manticore — Iran-Aligned Threat Actor Targeting Israel
- Check Point Research: Iranian Educated Manticore Targets Leading Tech Academics
- Check Point Research: Nimbus Manticore Deploys New Malware Targeting Europe
- Google TAG: Untangling Iran APT42 Operations
- Canadian Centre for Cyber Security: Iran's Social Engineering and Spear-Phishing Campaigns
- Harfang Lab: RedKitten AI-Accelerated Campaign Targeting Iranian Protests
- Unit 42: LNK Malware Execution Techniques
- Iran International: IRGC Monitoring and Suppression of Dissent
- BBC: IRGC Suppression of Protests
- DW: How Dangerous Are Iranian Secret Services in Germany
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Detection coverage for TL-2026-0159
As of 2026-02-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0159 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.