Thenationalnews Crescent Harvest Malware Targets Iranian Protest Supporters
Article Content
Browse articles
A new malware campaign named 'Crescent Harvest' has been identified, targeting supporters of protests in Iran. The malware specifically affects Farsi-speaking users seeking information about the demonstrations, coinciding with an internet blackout in the region. Security experts from Acronis first detected the malware in early January 2026.
Ask AI about this cluster
Answers cite the sources they use
Updated 197d ago How this analysis works
Timeline
2026-01-01
Crescent Harvest malware campaign detected
2026-01-01
Targeting of Farsi-speaking users begins
2026-02-17
Articles published detailing the malware campaign
More articles in this cluster (10)
Following this threat?
Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…