Iran-Linked 'Handala Hack' Group Uses Telegram Backdoor to Steal Passwords and Spy on Targets
Security researchers at Group-IB have tied the Iran-linked persona known as Handala Hack to a surveillance backdoor called HEAVYGRAM and a helper tool named CRUDEEXCLUDE. HEAVYGRAM can run remote commands, gather system and network details, steal Telegram session files and passwords, take screenshots, and stay hidden on infected machines using Windows autorun registry keys.
CRUDEEXCLUDE, first spotted in mid to late 2024, is disguised as a normal Windows application and is used to quietly add exclusions to Microsoft Defender, making it easier for HEAVYGRAM and later-stage malware to run undetected. The UK's National Cyber Security Centre tracks the same malware family under a different name, describing it as a flexible tool that supports a range of operations.
According to the findings, attackers approach victims through Telegram, WhatsApp, and Instagram, posing as tech support or trusted contacts, and then send fake installers disguised as legitimate apps such as Pictory, KeePass, or Telegram itself. Handala Hack is assessed to be run by an Iranian state-linked group and has previously carried out destructive data-wiping and leak operations, with the FBI having separately warned about related Iranian intelligence-linked campaigns targeting dissidents and journalists.