AI Weekly Malaysia

Back to items Summaries

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

ID
25851
Status
summarized
Published
17 Sep 2026, 10:03 PM
Fetched
18 Sep 2026, 12:41 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.0
Created
18 Sep 2026, 12:45 PM
Tags
Audience
developers

What happened

Group-IB attributed the Iran-linked Handala Hack persona to HEAVYGRAM, a Telegram-based Windows backdoor capable of remote command execution, session file exfiltration, and persistence via autorun keys, delivered through social engineering on Telegram, WhatsApp, and Instagram. The malware is staged via CRUDEEXCLUDE, a Delphi utility that configures Microsoft Defender exclusion paths and disguises itself as legitimate apps like Pictory, KeePass, and Telegram.

Why it matters

This is targeted espionage against Iranian dissidents and journalists, not a broad developer-facing threat. Unless you are building messaging-platform security tooling or advising at-risk users, there is no concrete action to take. The social-engineering delivery vector (fake installers for known apps) is a reminder to verify installer provenance, but that is routine hygiene, not a change in practice.

Discussion angle

Brief mention only: how fake installer trojans for well-known apps (KeePass, Telegram) remain an effective delivery vector and why Defender exclusion-path manipulation is a simple but powerful evasion technique worth understanding if you do endpoint security work.

Top