Hack.lu 2026

From the Rebellious Cities: Anatomy of a State-Aligned Espionage Campaign

When protesters take to the streets, someone is always watching. CRESCENTHARVEST is a cyberespionage campaign that weaponizes Iran's ongoing civil unrest, targeting Farsi-speaking supporters of the protest movement with carefully crafted lures. Victims receive what appears to be a frontline dispatch from inside Iran: protest footage, images from the streets, and a Farsi report from "the rebellious cities." Hidden inside are two files that, once clicked, compromise the victim's machine through an attack chain so seamlessly crafted that they never suspect a thing.

What unfolds beneath the surface is a sophisticated operation where trust is the exploit and sympathy is the attack vector. This paper peels back the layers of a campaign designed to blend in, stay hidden, and steal everything, tracing the full attack chain, the implant's capabilities, and the infrastructure fingerprints that tie it to a state-aligned actor with a long history of hunting its own people.


CRESCENTHARVEST is a cyberespionage campaign caught in the act of exploiting Iran's ongoing civil unrest to hunt down the very people trying to follow it. The infection begins with a RAR file that looks exactly like what a protest supporter would want: verified protest footage, authentic street images, and a Farsi-language report styled like a social media dispatch from inside Iran.

This talk will take the audience through the full operation, from the social engineering and psychological manipulation, to the binary internals, and draw conclusions and lessons at each stage of the attack. We walk through delivery and initial infection via .lnk files disguised as fake images of protests, an unusual event-driven persistence mechanism triggered by network connectivity rather than a scheduled timer, DLL sideloading via a signed, deprecated Google binary, and a two-module payload architecture where Module 1 specifically targets Chrome's app-bound encryption through COM elevation before passing the decrypted key to Module 2 over a named pipe.

Module 2 is an as-of-yet-unknown, full RAT and infostealer combination, with several interesting technical elements: PEB walking to evade static analysis, XOR-encrypted API resolution, Job Object abuse for anti-debugging, system-wide keylogging, Telegram session theft, browser credential harvesting across Chrome, Firefox and Edge, and WMI-based security product enumeration that lets the operator adjust behavior based on what defenses are present.

We also examine the operational mistakes that have popped up throughout our investigation: hardcoded C2 endpoints that go unused, a user-agent field that accidentally broadcasts the C2 domain to every host it contacts, and PDB artifacts pointing directly to the developer's build directory. Infrastructure analysis, code overlaps with documented Iranian-affiliated campaigns, and victimology all point toward a state-aligned actor, consistent with a decade-long IRGC pattern of hunting dissidents, journalists, and protest supporters at home and abroad. Attendees leave with full IOCs, detection guidance, and a detailed breakdown of the tradecraft behind a campaign that weaponizes information hunger as its primary exploit.

Eliad Kimhy

Eliad Kimhy is a Senior Security Researcher at Acronis, where he conducts research into emerging threats and cybercrime, and shares insights through conference talks and published reports. Eliad has worked with security teams for close to a decade, helping build and lead the development of threat intelligence production, and the publication of research-based content for technical and general audiences. He has spoken at conferences such as VirusBulletin, CARO, Insomnihack, Thotcon, BsidesSF, BsidesLV, and IT-SA. He is the co-creator and producer of the Webby Honoree podcast Malicious Life, which explores the untold stories and cultural history of hacking.