← Blog · · df00tech

Iran-Linked 'Handala Hack' Persona Tied to New HEAVYGRAM Telegram Backdoor

security-news campaign

What Happened

Researchers have attributed the Iran-linked "hacktivist" persona known as Handala Hack to a previously undocumented Telegram-based surveillance backdoor called HEAVYGRAM, alongside a Delphi-based utility named CRUDEEXCLUDE. According to the reporting, HEAVYGRAM includes built-in commands for remote command execution, system/network/process information discovery, exfiltration of data and Telegram session files, screenshot capture, and DLL sideloading. Full technical details of the campaign's delivery mechanism and victimology were not included in the available summary.

Why It Matters

Handala Hack has been associated with Iran-linked activity presenting as hacktivism, and the use of Telegram as a command-and-control channel is notable: it blends malicious traffic with legitimate messaging-app usage, which can complicate network-based detection. The theft of Telegram session files is particularly concerning, as it can allow an attacker to hijack a victim's Telegram account/session without needing credentials, extending the backdoor's reach into a target's communications and contacts. Organizations and individuals who may be targets of Iran-linked influence or espionage operations — including activists, journalists, and organizations in sectors previously targeted by Iran-nexus actors — should treat this as a relevant threat update.

What Defenders Should Watch For

  • Unusual outbound connections to Telegram API endpoints from hosts that don't normally use Telegram, especially from non-interactive or service-account contexts.
  • DLL sideloading behavior: legitimate signed executables loading unexpected DLLs from non-standard directories.
  • Processes enumerating system, network, and process information shortly after an unexpected binary execution — a common discovery pattern for this backdoor class.
  • Unexpected access to or exfiltration of local Telegram session/data files (e.g., tdata directories or similar session storage paths).
  • Screenshot capture utilities or API calls invoked by unfamiliar processes.
  • General hygiene mitigations: application allow-listing to curb DLL sideloading, monitoring/restricting Telegram Desktop usage on sensitive endpoints where not business-justified, and educating high-risk users (journalists, activists, dissidents) who are common targets of Iran-linked personas.

Developing Intel

This is a net-new attribution based on recent open-source reporting, and further technical details (delivery vector, infrastructure, full victimology) may emerge as researchers continue to analyze the campaign. df00tech will track this story for any indicators or TTPs that map to a formal detection rule. Read the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.