Iran-Linked Handala Hack Utilizes HEAVYGRAM Telegram Backdoor for Password Theft and Espionage
A cyber espionage campaign linked to Iran's MOIS employs the HEAVYGRAM Telegram backdoor to steal passwords and exfiltrate data, leveraging social engineering and Telegram's encrypted channels for command-and-control. The malware uses Python-based C2 communication, persistence via Windows Registry, and disguises itself as legitimate applications to target dissidents and journalists.
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.
"HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
*** END OF TRANSMISSION ***