Threat Intelligence

Iran-Linked 'Handala Hack' Group Uses Telegram Backdoor to Steal Passwords and Spy on Targets

The Hacker News · 18 Sept 2026
Key Takeaway Train staff to be wary of unsolicited tech support offers or software links sent via messaging apps, and only install applications from verified official sources.

Security researchers at Group-IB have tied the Iran-linked persona known as Handala Hack to a surveillance backdoor called HEAVYGRAM and a helper tool named CRUDEEXCLUDE. HEAVYGRAM can run remote commands, gather system and network details, steal Telegram session files and passwords, take screenshots, and stay hidden on infected machines using Windows autorun registry keys.

CRUDEEXCLUDE, first spotted in mid to late 2024, is disguised as a normal Windows application and is used to quietly add exclusions to Microsoft Defender, making it easier for HEAVYGRAM and later-stage malware to run undetected. The UK's National Cyber Security Centre tracks the same malware family under a different name, describing it as a flexible tool that supports a range of operations.

According to the findings, attackers approach victims through Telegram, WhatsApp, and Instagram, posing as tech support or trusted contacts, and then send fake installers disguised as legitimate apps such as Pictory, KeePass, or Telegram itself. Handala Hack is assessed to be run by an Iranian state-linked group and has previously carried out destructive data-wiping and leak operations, with the FBI having separately warned about related Iranian intelligence-linked campaigns targeting dissidents and journalists.

Iran Telegram malware backdoor social engineering Handala Hack Windows Defender evasion

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.