Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
- ID
- 25851
- Status
- summarized
- Published
- 17 Sep 2026, 10:03 PM
- Fetched
- 18 Sep 2026, 12:41 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 18 Sep 2026, 12:45 PM
- Tags
- Audience
- developers
What happened
Group-IB attributed the Iran-linked Handala Hack persona to HEAVYGRAM, a Telegram-based Windows backdoor capable of remote command execution, session file exfiltration, and persistence via autorun keys, delivered through social engineering on Telegram, WhatsApp, and Instagram. The malware is staged via CRUDEEXCLUDE, a Delphi utility that configures Microsoft Defender exclusion paths and disguises itself as legitimate apps like Pictory, KeePass, and Telegram.
Why it matters
This is targeted espionage against Iranian dissidents and journalists, not a broad developer-facing threat. Unless you are building messaging-platform security tooling or advising at-risk users, there is no concrete action to take. The social-engineering delivery vector (fake installers for known apps) is a reminder to verify installer provenance, but that is routine hygiene, not a change in practice.
Discussion angle
Brief mention only: how fake installer trojans for well-known apps (KeePass, Telegram) remain an effective delivery vector and why Defender exclusion-path manipulation is a simple but powerful evasion technique worth understanding if you do endpoint security work.