New espionage malware targeting Iranian protesters and diaspora activists

Acronis Threat Intelligence has uncovered a new malware campaign, dubbed CRESCENTHARVEST, using protest-themed files to target Iranian protesters and diaspora activists across multiple countries.

Acronis researchers analysed the activity and found it leverages authentic protest media and Farsi-language "frontline updates" as a lure, before deploying a custom espionage payload designed for long-term surveillance. Full research here.

Key findings:

Protest-themed images and videos were used as a lure to trick targets into opening malicious files
The malware was designed to look legitimate by abusing trusted software, helping it evade detection
Once installed, it enabled long-term surveillance and theft of sensitive data, including Telegram and browser information

What stands out is how directly the campaign weaponises protest-related information itself, exploiting demand for updates during political unrest and turning it into an infection vector.

Articles similaires

Malware Update

19 August 2026

Zimperium zLabs Uncovers ToxicPanda 2.0, a Significantly More Powerful Android Banking Trojan

News Highlights : • Malware expands targeting to 349 banking, financial, e-wallet, and (…)

Malware Update

19 March 2026

New Zimperium Report Finds Banking Malware Expands Global Reach, Targeting 1,200+ Financial Apps

New Zimperium, the world leader in AI-empowered mobile security, today Report Finds Banking (…)

Malware Update

17 March 2026

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools