
highThreat Intelligence
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Security researchers from Kaspersky and ESET have linked the Iran-aligned 'hacktivist' persona Handala Hack to a Telegram-based surveillance backdoor named HEAVYGRAM and a Delphi-based utility called CRUDEEXCLUDE. The malware supports remote command execution, system and network discovery, data and Telegram session file exfiltration, screenshot capture, DLL sideloading, and password theft. Active exploitation is reported via Telegram lures, with no official patch available; mitigation focuses on user awareness and endpoint monitoring.
The Hacker News2 min read