hacker-news · Crawled Sep 18, 2026

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

1 IoCs 1 Actors
Read original article ↗

AI Summary

The Iran-linked threat actor known as Handala Hack, attributed to the MOIS-affiliated group Void Manticore, has been linked to a multi-stage malware campaign using the Telegram-based backdoor HEAVYGRAM and the Delphi-based utility CRUDEEXCLUDE. HEAVYGRAM is a Python-based backdoor that uses Telegram for command-and-control, enabling remote command execution, data exfiltration (including Telegram and WhatsApp data and saved passwords), screenshot capture, and persistence via Windows Registry keys. The malware is delivered through social engineering on messaging platforms, often disguised as legitimate applications like Pictory, KeePass, or Telegram, and leverages PowerShell and DLL sideloading for execution and evasion. CRUDEEXCLUDE prepares the environment by configuring Microsoft Defender exclusions and staging HEAVYGRAM and other payloads.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain api[.]ipify[.]org Details →

MITRE ATT&CK TTPs 12 techniques