Researchers link the Iran-affiliated Handala Hack group to HEAVYGRAM, a Telegram-based backdoor used to target dissidents and steal passwords.

Reader brief
Through the Reader lens: Cybersecurity researchers have linked the Iranian group known as Handala Hack to HEAVYGRAM, a Python-based backdoor that uses Telegram for command-and-control operations. The malware, along with a deployment utility called CRUDEEXCLUDE, is designed to steal browser data, record audio, capture screenshots, and bypass security tools. The threat actors, operating on behalf of Iran's Ministry of Intelligence and Security, primarily target Iranian dissidents, journalists, and opposition groups through social engineering.
What was said2
Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.
Group-IB
2 quotes“HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence via Windows autorun registry keys”
In the article
…The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. " HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence via Windows autorun registry keys ," Group-IB said. On the other hand, CRUDEEXCLUDE is a Delphi-based Windows utility employed to prepare environments for the deployment of subsequent stages such as HEAVYGRAM. First observed in late July 2024, the…
“The newly identified samples demonstrate a flexible, multi-stage infection chain in which operators combine tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest”
In the article
…infrastructure has revealed two main setups: one where C2 relies on a single Telegram bot and group, and another where one bot handles check-ins while a secondary bot manages logging and stage polling with a group. " The newly identified samples demonstrate a flexible, multi-stage infection chain in which operators combine tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest ," Group-IB said. "The extensive use of Telegram across operations is particularly notable, providing operators with a natively encrypted command-and-control channel that has low setup, maintenance and rotation cost."…
Sources1
- [1]The Hacker NewsneutralIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords