CRESCENTHARVEST — Iranian IRGC-Aligned Cyberespionage Campaign Targeting Protestors & Dissidents via DLL Sideloading with Signed Google Executable

CRESCENTHARVEST (TL-2026-0159) is a high-severity advanced persistent threat campaign, first published 2026-02-28. It carries a reported Iran nexus and is not formally attributed, maps to 31 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-0159

Threat ID
TL-2026-0159
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-02-28
Last reviewed
2026-02-28
Attribution confidence
NONE
Nation-state nexus
Iran
Detection rules
9
Indicators of compromise
23

Acronis Threat Research Unit (TRU) uncovered CRESCENTHARVEST, a cyberespionage campaign targeting supporters of Iran's ongoing protests. The attack delivers a dual-module malware payload — a RAT and infostealer — via DLL sideloading using a signed Google Chrome Software Reporter Tool executable, with initial access through malicious .LNK files disguised as protest-related media bundled in RAR archives.

How CRESCENTHARVEST works

CRESCENTHARVEST is a targeted cyberespionage campaign discovered by Acronis TRU in early 2026, designed to surveil and compromise Farsi-speaking Iranians sympathetic to the ongoing anti-IRGC protests. The campaign leverages geopolitical developments to deliver malware through social engineering, bundling malicious .LNK files alongside authentic protest images, videos, and a Farsi-language report titled 'the rebellious cities of Iran.'

The infection chain begins with spear-phishing or protracted social engineering, delivering a RAR archive containing decoy media and two malicious .LNK shortcuts disguised as video and image files. When clicked, the .LNK files invoke nested conhost.exe processes with --headless switches to obscure execution, spawning cmd.exe then PowerShell to extract a ZIP payload embedded within the .LNK to the user's %TEMP% folder.

Persistence is established through a novel scheduled task mechanism: instead of traditional startup triggers, the task fires on Windows NetworkProfile EventID 10000, executing the payload whenever the system establishes network connectivity — including after reboot or offline-to-online transitions.

The payload uses DLL sideloading via software_reporter_tool.exe, a legitimate Google-signed binary (Chrome's deprecated Software Reporter Tool, removed in 2023). The executable loads two malicious DLLs using LoadLibraryExA without path restrictions, enabling search order hijacking.

Module 1 (urtcbased140d_d.dll) is a C++ implant that bypasses Chrome's app-bound encryption by instantiating the browser's COM elevation broker (IElevator interface) to decrypt the master key from the Local State file. The decrypted key is saved to APPDATA\decrypted_appbound_key.txt and shared with Module 2 via a named pipe. This module shows heavy code overlap with the open-source ChromElevator project. PDB path artifact: E:\new\stealer\Stealer\x64\Release.

Module 2 (version.dll) is the main RAT/infostealer with extensive capabilities: keylogging via WH_KEYBOARD_LL hooks (logging to C:\Windows\System32\spool\Drivers\color\daT.txt), browser credential harvesting (Chrome, Firefox, Edge), Telegram Desktop session theft, user enumeration, shell command execution, directory traversal, DLL loading, WMI-based security product detection, and system profiling. It uses PEB walking to resolve APIs dynamically and XOR decryption with key '!@#$6756' for string obfuscation. Anti-analysis employs Windows Job Objects to restrict process memory ('Process on a Diet' technique).

C2 communications use JSON over HTTPS via WinHTTP APIs. The implant registers with {"Identifier":"admin"} and receives commands like KeyLog, Tel_s, F_log, Cook, GetUser, shell. A notable bug causes the malware to send the C2 domain as its User-Agent instead of the intended Chrome UA string, reducing evasion effectiveness. Multiple predefined C2 endpoints (/register_agent, /info, /Out, /upload, etc.) exist but most operations route through /Out and /upload.

Infrastructure centers on servicelog-information[.]com resolving to 185.242.105.230 hosted in Riga, Latvia on ASN AS42532 (VEESP-LV-AS), with historical Cloudflare CDN proxying via AS13335. The code shows methodological similarities to campaigns attributed to Iranian threat groups documented by Check Point Research (Educated Manticore, Nimbus Manticore), including similar LNK unpacking scripts, JSON-based C2 communication, and WinHTTP exfiltration patterns.

MITRE ATT&CK techniques used in TL-2026-0159

collection

T1005 Data from Local System; T1056.001 Keylogging; T1560 Archive Collected Data

stealth

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL; T1622 Debugger Evasion

exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

execution

T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File

discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.001 Local Account; T1518.001 Security Software Discovery

command-and-control

T1071.001 Web Protocols; T1132.001 Standard Encoding; T1573.002 Asymmetric Cryptography

credential-access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

privilege-escalation

T1546 Event Triggered Execution

initial-access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

resource-development

T1583.003 Virtual Private Server; T1587.001 Malware; T1588.002 Tool

Timeline of CRESCENTHARVEST

  • Google deprecates and removes Software Reporter Tool (software_reporter_tool.exe) from Chrome, the binary later abused in this campaign for DLL sideloading.
  • The Google code-signing certificate on software_reporter_tool.exe expires in 2024, but the binary remains signed and usable for sideloading.
  • Threat actor prepares Farsi-language protest report ('the rebellious cities of Iran') and bundles authentic protest media with malicious .LNK files in RAR archives.
  • Earliest protest images used in CRESCENTHARVEST decoy materials dated to January 9, 2026, establishing the campaign's minimum start date.
  • C2 domain servicelog-information[.]com observed active, resolving to 185.242.105.230 (VEESP-LV-AS, Latvia) with intermittent Cloudflare CDN proxying.
  • Acronis TRU begins actively monitoring the CRESCENTHARVEST campaign after discovering malware samples and bundled decoy files.
  • Acronis TRU publishes full technical analysis of CRESCENTHARVEST campaign including IOCs, attack chain, and attribution analysis. Source: https://www.acronis.com/en/tru/posts/crescentharvest-iranian-protestors-and-dissidents-targeted-in-cyberespionage-campaign/
  • Threadlinqs Intelligence publishes TL-2026-0159 with full MITRE mapping, IOCs, detections, and simulation coverage.
  • As of 2026-05-29, CRESCENTHARVEST remains ACTIVE: the Acronis TRU report and corroborating coverage (Hacker News, The Record) describe an ongoing Iranian IRGC-aligned campaign with no reported takedown, sinkhole, or disruption of C2 servicelog-information[.]com (Latvia VEESP). With no CVE to patch, no successor, and IRGC dissident-surveillance and Manticore APT activity escalating Feb-May 2026, the threat persists.

Sources cited for CRESCENTHARVEST

More in apt

Detection coverage for TL-2026-0159

As of 2026-02-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0159 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats