By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Iran-Linked Handala Hack Uses HEAVYGRAM Telegram Backdoor

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a sophisticated Telegram-based surveillance backdoor named HEAVYGRAM. This malware, alongside a Delphi-based utility called CRUDEEXCLUDE, facilitates extensive data exfiltration and system compromise. Security researchers at SentinelOne detailed these findings, highlighting the advanced capabilities of the tools employed by Handala Hack. HEAVYGRAM is designed with a suite of built-in commands that enable remote command execution, allowing attackers to control infected systems from afar. It also supports the discovery of system, network, and process information, providing attackers with a detailed understanding of the target environment. A primary function of HEAVYGRAM is the exfiltration of sensitive data, including user files and Telegram session information, which can grant access to encrypted communications and stored credentials. The backdoor also possesses the capability to capture screenshots, offering visual surveillance of the user's activity. Furthermore, it supports DLL sideloading, a technique that allows malicious code to be executed under the guise of legitimate software components. The CRUDEEXCLUDE utility, written in Delphi, complements HEAVYGRAM by focusing on password theft. It is capable of stealing passwords stored by various applications, including web browsers and FTP clients, thereby broadening the scope of compromised information. This dual-tool approach underscores the comprehensive nature of the surveillance operations attributed to Handala Hack. The attribution to Iran-linked actors suggests a state-sponsored or state-tolerated cyber espionage campaign. Such operations are often aimed at gathering intelligence on political dissidents, journalists, or individuals of strategic interest. The use of Telegram as a platform for the backdoor is notable, as it is a widely used messaging application, potentially increasing the attack surface and the likelihood of targeting unsuspecting users. The combination of remote control, data exfiltration, surveillance, and credential theft makes HEAVYGRAM and CRUDEEXCLUDE potent tools for cyber espionage. SentinelOne's analysis provides critical insights into the tactics, techniques, and procedures (TTPs) employed by Handala Hack, enabling cybersecurity professionals to develop more effective defenses against such threats. The ongoing evolution of these tools and the persistent nature of such campaigns necessitate continuous monitoring and adaptation of security measures.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.