Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Steals Passwords

Researchers link Handala Hack to HEAVYGRAM, a Telegram-controlled Windows backdoor capable of stealing passwords, messages, screenshots and other sensitive data.

Cybersecurity researchers have linked the Iran-associated Handala Hack persona to a sophisticated Windows surveillance backdoor known as HEAVYGRAM, capable of stealing passwords, capturing screenshots, recording audio and extracting Telegram and WhatsApp data.

Group-IB's analysis connects the malware activity to Handala Hack, while U.S., U.K. and Dutch authorities have separately attributed related operations to cyber actors acting on behalf of Iran's Ministry of Intelligence and Security (MOIS). The U.K. National Cyber Security Centre (NCSC) tracks the same malware family as CHOSEN BRICK.

What Is HEAVYGRAM?

HEAVYGRAM is a Python-based Windows backdoor first detected in the wild in September 2023. Its defining feature is the use of Telegram bots for command-and-control (C2), allowing operators to remotely control infected computers while blending communications with legitimate Telegram traffic.

Once installed, HEAVYGRAM can:

  • Steal saved passwords and browser information
  • Capture screenshots
  • Activate the device microphone
  • Collect Telegram and WhatsApp data
  • Execute arbitrary commands
  • Upload and download files
  • Enumerate processes and system information
  • Install additional malware
  • Delete files
  • Maintain persistence through Windows Registry autorun keys

The NCSC says variants of the malware can also steal email content and, in at least one observed sample, perform destructive data-wiping actions.

How the Attack Works

The campaigns rely heavily on targeted social engineering.

Attackers contact victims through platforms such as Telegram and WhatsApp, often pretending to be trusted contacts or technical-support personnel. They build trust before convincing the victim to download a malicious file disguised as legitimate software or a document.

The attack chain typically follows:

Targeted social engineering → Malicious file → Windows execution → Defender evasion → HEAVYGRAM installation → Telegram C2 → Surveillance and data theft

Malicious files have reportedly masqueraded as applications including Telegram, KeePass, Norton Antivirus, Pictory and RunwayML. Some attacks even used fabricated MRI scan results as lures.

CRUDEEXCLUDE Prepares the System

Researchers also identified a Delphi-based Windows utility called CRUDEEXCLUDE being used in the infection chain.

CRUDEEXCLUDE is designed to prepare compromised systems for additional malware such as HEAVYGRAM. One of its key functions is configuring Microsoft Defender exclusion paths, helping subsequent malicious components avoid antivirus scanning.

HEAVYGRAM itself can establish persistence using:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

This allows the malware to restart when the compromised user logs into Windows.

Who Is Being Targeted?

The joint NCSC, FBI and Dutch AIVD advisory says related malware operations have targeted individuals worldwide, particularly:

  • Iranian dissidents
  • Activists
  • Journalists
  • Opposition figures
  • Other individuals considered intelligence targets

The agencies say the activity has been observed against targets in countries including the United Kingdom, United States and Netherlands since at least 2025.

Some information stolen from previous victims has subsequently appeared on pro-Iranian leak sites, according to the NCSC.

What Defenders Should Monitor

Security teams should investigate:

  • Unexpected Windows Registry Run-key modifications
  • New Microsoft Defender exclusions
  • Suspicious PowerShell execution
  • Telegram API traffic from unusual processes
  • Unexpected microphone or screenshot activity
  • Access to browser credential stores
  • Attempts to copy Telegram or WhatsApp data
  • Unknown executables masquerading as legitimate applications
  • Suspicious files under unusual Windows directories

Organizations should also train high-risk personnel to independently verify unexpected messages or software sent through Telegram, WhatsApp and other messaging platforms.

Security Takeaway

HEAVYGRAM demonstrates how legitimate cloud and messaging platforms can be repurposed as attacker infrastructure.

By combining social engineering, Defender evasion, persistent Windows access and Telegram-based C2, operators can maintain surveillance over compromised devices while stealing credentials, communications and other sensitive information.

The attribution should be treated carefully: Group-IB links HEAVYGRAM activity to Handala Hack, while the FBI and partner agencies attribute the broader related activity to actors working on behalf of Iran's MOIS.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.