Cybersecurity
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Published
1 day agoon
By
Jon Tru
An Iran-linked cyber threat group has been connected to a sophisticated surveillance campaign involving a Telegram-controlled backdoor capable of stealing passwords, collecting sensitive application data and remotely controlling compromised Windows systems.
Security researchers at Group-IB attributed the malware activity to the threat actor known as Handala Hack, linking the operation to a Python-based backdoor called HEAVYGRAM and a Delphi-based staging utility named CRUDEEXCLUDE.
The United Kingdom’s National Cyber Security Centre (NCSC) tracks the same malware family under the name CHOSEN BRICK.
HEAVYGRAM Provides Extensive Remote Access
HEAVYGRAM functions as a multi-purpose Windows backdoor that uses Telegram as its command-and-control (C2) infrastructure.
Once installed, the malware can receive commands from attackers through a Telegram bot and perform a wide range of actions on an infected computer. Its capabilities include:
- Executing commands remotely
- Starting arbitrary applications and processes
- Collecting system, network and process information
- Capturing screenshots
- Stealing browser information and saved passwords
- Downloading and uploading files
- Collecting Telegram and WhatsApp data
- Accessing Telegram Desktop session information
- Activating the system microphone
- Downloading additional malicious payloads
- Removing files from compromised systems
- Establishing persistence through Windows Registry autorun keys
The malware also sends information about infected machines back to its operators, allowing them to monitor whether compromised systems remain accessible.
CRUDEEXCLUDE Helps Prepare Infected Systems
Group-IB also identified CRUDEEXCLUDE, a Delphi-based Windows utility used during the early stages of the infection process.
The program is frequently disguised as legitimate software and presented with a graphical interface to make it appear trustworthy. Its primary purpose is to prepare the system for additional malware.
One of its key functions is modifying Microsoft Defender exclusion settings, preventing security software from scanning directories used to store malicious payloads.
CRUDEEXCLUDE was first observed in July 2024 and was later documented by Google in December 2025 in connection with campaigns involving HEAVYGRAM and another malware family known as SHADEGENES.
Attackers Rely on Social Engineering
The campaigns typically begin with social engineering conducted through popular communication platforms, including Telegram, WhatsApp and Instagram.
Threat actors may approach victims while pretending to be trusted contacts, technical support personnel or other legitimate individuals. They then encourage targets to install software presented as a genuine application.
Researchers observed malicious installers masquerading as applications such as Pictory, KeePass and Telegram. Behind the legitimate-looking interface, the packages contain components used to deploy the malware.
This approach combines social engineering with application impersonation, making it easier to persuade targeted individuals to execute the initial payload.
Telegram Used as Malware Control Channel
A notable feature of HEAVYGRAM is its extensive dependence on Telegram for communications with compromised systems.
The malware can interpret commands sent through an attacker-controlled Telegram bot. Different command prefixes activate different functions.
For example, one command mechanism can execute operating-system commands, while another enables a broader collection of backdoor functions, including process execution, payload deployment, registry persistence and collection of Telegram data.
The operators can also remotely update the Telegram bot credentials and associated user information used to control the malware.
Attachments sent through the Telegram infrastructure are processed according to filename patterns, giving operators another method of delivering files and additional payloads.
Malware Sends Regular Status Updates
HEAVYGRAM maintains communication with its operators through persistent C2 functions.
After establishing a connection, the malware sends an initial notification containing information such as the compromised computer’s domain name. A background process subsequently sends periodic status messages, including a heartbeat approximately every 24 hours.
This mechanism allows attackers to determine whether an infected system remains operational and under their control.
Multiple Delivery Methods Identified
Researchers have identified several methods used to deliver HEAVYGRAM.
The infection chain has included:
- WSF and VBS scripts
- VBScript and HTA files
- Executables containing embedded archives
- CRUDEEXCLUDE packages containing embedded malicious archives
The different delivery mechanisms provide operators with flexibility when adapting campaigns to specific victims or environments.
Handala Hack Linked to Iran’s MOIS
Handala Hack emerged after the October 2023 attacks in Israel and has been associated by researchers with an Iran-linked threat actor known as Void Manticore.
The group has previously been connected to destructive cyber operations, data theft and hack-and-leak campaigns.
The FBI has also warned about Iranian cyber actors allegedly working on behalf of Iran’s Ministry of Intelligence and Security (MOIS). According to the agency, such operations have targeted Iranian dissidents, journalists critical of the Iranian government and opposition organizations for intelligence gathering and other purposes.
In a separate assessment, Canada’s Rapid Response Mechanism previously identified activity involving the targeting and exposure of journalists associated with Iran International.
Two Telegram Infrastructure Models
Analysis of the command infrastructure uncovered two primary configurations.
In one setup, a single Telegram bot and group are used to manage communications with infected systems. A second configuration separates responsibilities between multiple bots, with one handling victim check-ins and another supporting logging and requests for additional stages.
Using Telegram provides operators with an inexpensive and readily available communication platform while allowing them to manage infected machines without maintaining conventional dedicated C2 servers.
Security Implications
Group-IB said the newly identified samples demonstrate a flexible infection chain combining social engineering, legitimate-application impersonation, security-tool evasion and persistent access.
The extensive use of Telegram is particularly significant because the platform can provide attackers with a convenient communication channel that is relatively inexpensive to establish and replace.
For organizations and individuals, the campaign highlights the importance of verifying software downloads, avoiding unexpected installation requests received through messaging platforms, monitoring Microsoft Defender exclusions and restricting the execution of untrusted scripts and applications.
Organizations should also monitor unusual Telegram-related network activity and investigate unexpected persistence mechanisms involving Windows Registry autorun locations.
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
CISO’s Expert Guide to Agentic Pentesting for Websites
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
First Agentic AI Data Breach Reported to Spanish Regulator

