Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Steals Passwords
Researchers link Handala Hack to HEAVYGRAM, a Telegram-controlled Windows backdoor capable of stealing passwords, messages, screenshots and other sensitive data.

Cybersecurity researchers have linked the Iran-associated Handala Hack persona to a sophisticated Windows surveillance backdoor known as HEAVYGRAM, capable of stealing passwords, capturing screenshots, recording audio and extracting Telegram and WhatsApp data.
Group-IB's analysis connects the malware activity to Handala Hack, while U.S., U.K. and Dutch authorities have separately attributed related operations to cyber actors acting on behalf of Iran's Ministry of Intelligence and Security (MOIS). The U.K. National Cyber Security Centre (NCSC) tracks the same malware family as CHOSEN BRICK.
What Is HEAVYGRAM?
HEAVYGRAM is a Python-based Windows backdoor first detected in the wild in September 2023. Its defining feature is the use of Telegram bots for command-and-control (C2), allowing operators to remotely control infected computers while blending communications with legitimate Telegram traffic.
Once installed, HEAVYGRAM can:
- Steal saved passwords and browser information
- Capture screenshots
- Activate the device microphone
- Collect Telegram and WhatsApp data
- Execute arbitrary commands
- Upload and download files
- Enumerate processes and system information
- Install additional malware
- Delete files
- Maintain persistence through Windows Registry autorun keys
The NCSC says variants of the malware can also steal email content and, in at least one observed sample, perform destructive data-wiping actions.
How the Attack Works
The campaigns rely heavily on targeted social engineering.
Attackers contact victims through platforms such as Telegram and WhatsApp, often pretending to be trusted contacts or technical-support personnel. They build trust before convincing the victim to download a malicious file disguised as legitimate software or a document.
The attack chain typically follows:
Targeted social engineering → Malicious file → Windows execution → Defender evasion → HEAVYGRAM installation → Telegram C2 → Surveillance and data theft
Malicious files have reportedly masqueraded as applications including Telegram, KeePass, Norton Antivirus, Pictory and RunwayML. Some attacks even used fabricated MRI scan results as lures.
CRUDEEXCLUDE Prepares the System
Researchers also identified a Delphi-based Windows utility called CRUDEEXCLUDE being used in the infection chain.
CRUDEEXCLUDE is designed to prepare compromised systems for additional malware such as HEAVYGRAM. One of its key functions is configuring Microsoft Defender exclusion paths, helping subsequent malicious components avoid antivirus scanning.
HEAVYGRAM itself can establish persistence using:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
This allows the malware to restart when the compromised user logs into Windows.
Who Is Being Targeted?
The joint NCSC, FBI and Dutch AIVD advisory says related malware operations have targeted individuals worldwide, particularly:
- Iranian dissidents
- Activists
- Journalists
- Opposition figures
- Other individuals considered intelligence targets
The agencies say the activity has been observed against targets in countries including the United Kingdom, United States and Netherlands since at least 2025.
Some information stolen from previous victims has subsequently appeared on pro-Iranian leak sites, according to the NCSC.
What Defenders Should Monitor
Security teams should investigate:
- Unexpected Windows Registry Run-key modifications
- New Microsoft Defender exclusions
- Suspicious PowerShell execution
- Telegram API traffic from unusual processes
- Unexpected microphone or screenshot activity
- Access to browser credential stores
- Attempts to copy Telegram or WhatsApp data
- Unknown executables masquerading as legitimate applications
- Suspicious files under unusual Windows directories
Organizations should also train high-risk personnel to independently verify unexpected messages or software sent through Telegram, WhatsApp and other messaging platforms.
Security Takeaway
HEAVYGRAM demonstrates how legitimate cloud and messaging platforms can be repurposed as attacker infrastructure.
By combining social engineering, Defender evasion, persistent Windows access and Telegram-based C2, operators can maintain surveillance over compromised devices while stealing credentials, communications and other sensitive information.
The attribution should be treated carefully: Group-IB links HEAVYGRAM activity to Handala Hack, while the FBI and partner agencies attribute the broader related activity to actors working on behalf of Iran's MOIS.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


