Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Summary
The Iran-linked Handala Hack persona is associated with a Telegram backdoor named HEAVYGRAM and a utility called CRUDEEXCLUDE. HEAVYGRAM can execute remote commands, gather system information, exfiltrate data and Telegram session files, capture screenshots, and perform DLL sideloading.
IFF Assessment
FOE
The article describes a sophisticated backdoor capable of extensive data exfiltration and surveillance, posing a direct threat to user security.
Defender Context
This incident highlights the persistent threat of nation-state-backed actors using custom malware to conduct espionage and data theft, particularly leveraging popular messaging platforms like Telegram. Defenders should be aware of sophisticated backdoors that can compromise sensitive information and user credentials.