Acronis researchers analysed the activity and found it leverages authentic protest media and Farsi-language "frontline updates" as a lure, before deploying a custom espionage payload designed for long-term surveillance. Full research here.
Key findings:
Protest-themed images and videos were used as a lure to trick targets into opening malicious files
The malware was designed to look legitimate by abusing trusted software, helping it evade detection
Once installed, it enabled long-term surveillance and theft of sensitive data, including Telegram and browser information
What stands out is how directly the campaign weaponises protest-related information itself, exploiting demand for updates during political unrest and turning it into an infection vector.






