← Today’s chart
TEC1 sourceIN ×117 SEPT 2026 19:33 IST

Iranian Hacktivists Linked to Heavygram Telegram Surveillance Backdoor

Headline by Prism · from 1 report

Researchers link the Iran-affiliated Handala Hack group to HEAVYGRAM, a Telegram-based backdoor used to target dissidents and steal passwords.

Reader brief

Through the Reader lens: Cybersecurity researchers have linked the Iranian group known as Handala Hack to HEAVYGRAM, a Python-based backdoor that uses Telegram for command-and-control operations. The malware, along with a deployment utility called CRUDEEXCLUDE, is designed to steal browser data, record audio, capture screenshots, and bypass security tools. The threat actors, operating on behalf of Iran's Ministry of Intelligence and Security, primarily target Iranian dissidents, journalists, and opposition groups through social engineering.

What was said2

Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.

Group-IB

2 quotes
  • HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence via Windows autorun registry keys
    [1]The Hacker News· 17 Sept· opens on the quote
    In the article

    The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. " HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence via Windows autorun registry keys ," Group-IB said. On the other hand, CRUDEEXCLUDE is a Delphi-based Windows utility employed to prepare environments for the deployment of subsequent stages such as HEAVYGRAM. First observed in late July 2024, the

  • The newly identified samples demonstrate a flexible, multi-stage infection chain in which operators combine tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest
    [1]The Hacker News· 17 Sept· opens on the quote
    In the article

    infrastructure has revealed two main setups: one where C2 relies on a single Telegram bot and group, and another where one bot handles check-ins while a secondary bot manages logging and stage polling with a group. " The newly identified samples demonstrate a flexible, multi-stage infection chain in which operators combine tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest ," Group-IB said. "The extensive use of Telegram across operations is particularly notable, providing operators with a natively encrypted command-and-control channel that has low setup, maintenance and rotation cost."

Sources1

All filed from IndiaNamed Iran · United States · United Kingdom · Canada · Iran International · CHOSEN BRICK · CRUDEEXCLUDE · Federal Bureau of Investigation · Group-IB · Handala Hack · HEAVYGRAM · Ministry of Intelligence and Security · National Cyber Security Center · Rapid Response Mechanism · SHADEGENES · Void Manticore

← Today’s chart

Iranian Hacktivists Linked to Heavygram Telegram Surveillance Backdoor | Prism