A newly discovered Iranian threat actor is stealing Google and Instagram credentials belonging to Farsi-speaking targets worldwide using a new PowerShortShell stealer. The info stealer is also used for Telegram surveillance and collecting system information from compromised devices that get sent to attacker-controlled servers together with the stolen credentials. The attacks started in July as spear-phishing emails with malicious Winword attachments that exploit a Microsoft MS HTML remote code execution bug tracked as CVE-2021-40444. Almost half of the victims are located in the United States.”]

