Iran-linked threat actor Handala Hack operates a Telegram-based surveillance backdoor named HEAVYGRAM that delivers password theft and remote command execution capabilities to compromised systems, according to researchers tracking the actor's infrastructure and malware arsenal.
Security researchers connected Handala Hack to HEAVYGRAM and a supporting Delphi-built utility called CRUDEEXCLUDE. HEAVYGRAM functions as a full-featured remote access trojan disguised within Telegram communications. The backdoor extracts credentials, captures screenshots, collects system and network information, and executes arbitrary commands on infected machines. It also harvests Telegram session files, giving attackers persistent access to victims' messaging accounts.
The dual-tool approach reflects a deliberate operational design. CRUDEEXCLUDE handles preliminary reconnaissance and persistence mechanisms, while HEAVYGRAM delivers the primary post-exploitation framework. Attackers leverage DLL sideloading techniques to execute code with elevated privileges without triggering traditional endpoint detection.
Handala Hack maintains a public persona as a hacktivist entity, publishing claimed breaches and network intrusions on social media and underground forums. This public-facing activity masks deeper state-aligned objectives. Iranian threat actors regularly adopt hacktivist personas to claim plausible deniability for operations targeting regional governments, critical infrastructure, and foreign entities. The persona's attribution to sophisticated malware like HEAVYGRAM indicates the actor operates beyond simple website defacements or data dumps.
Telegram's integration into the backdoor's command-and-control infrastructure presents layered operational advantages. The platform's encryption and massive user base allow attackers to blend malicious traffic within legitimate Telegram communications. Compromised systems phone home through Telegram bots, receiving tasking and exfiltrating data while maintaining cover. This approach mirrors TTPs observed in other Iranian-nexus campaigns.
Organizations handling sensitive data in Middle Eastern, energy, telecommunications, and government sectors face direct targeting risk. HEAVYGRAM's password-stealing functionality enables lateral movement within networks. Attackers chain initial system compromise with credential harvesting to establish footholds in secured systems. Telegram session file theft grants access to victims' messaging networks, creating secondary attack vectors against contacts and organizational members.
Detection proves challenging because HEAVYGRAM uses legitimate infrastructure. Telegram appears in network logs as normal user activity. Behavioral analysis becomes the primary detection method. Anomalous process execution chains, unexpected DLL loading patterns, and screenshot capture activity reveal infection.
Organizations should implement application allowlisting to block unsigned executables. Network segmentation limits lateral movement following initial compromise. Password managers reduce attack surface from credential harvesting. Endpoint Detection and Response solutions tracking process execution chains and DLL sideloading patterns identify HEAVYGRAM activity. Blocking known malicious Telegram bot identifiers prevents command delivery.
Handala Hack's infrastructure continues evolving. Researchers expect variant samples incorporating new evasion techniques and command modules. The actor's consistent activity tempo and resource allocation suggest sustained intelligence collection objectives rather than disruptive operations.
