News

Iran's Handala Group Blinds Defender Then Plants HEAVYGRAM, a Telegram-Controlled Backdoor

Group-IB analysis, reported 17 September 2026, ties Iran-linked Handala Hack to CRUDEEXCLUDE, a Delphi loader that adds Microsoft Defender exclusions before launching HEAVYGRAM. The implant's Telegram bot uses @@, **, and ## command prefixes and a 24-hour heartbeat with the host domain.

Iran's Handala Group Blinds Defender Then Plants HEAVYGRAM, a Telegram-Controlled Backdoor

GBHackers (Mayura Kathir, 17 September 2026) and The Hacker News (Ravie Lakshmanan) reported Group-IB's analysis of Iran-linked Handala Hack activity that uses CRUDEEXCLUDE to add Microsoft Defender exclusions before deploying HEAVYGRAM, a Telegram-controlled Windows surveillance backdoor.

This is a vendor research writeup citing Group-IB, reinforced by an FBI HEAVYGRAM FLASH expansion on 15 September and by Department of Justice domain seizures on 19 March. It is not a product CVE advisory, and it is not a confirmed list of named corporate victims.

Group-IB assesses the Handala Hack persona as an online front for Void Manticore, also tracked as Storm-0842, Banished Kitten, and Red Sandstorm, and affiliated with Iran's Ministry of Intelligence and Security. The FBI attributes HEAVYGRAM operations to actors working for that ministry. GBHackers said the newly linked samples sit at moderate confidence.

CRUDEEXCLUDE is a Delphi first-stage loader with a graphical interface, often masquerading as Pictory, Telegram, KeePass, or WhatsApp. It uses PowerShell to add attacker-controlled paths to Microsoft Defender exclusions so later payloads in those paths are not scanned. It then decodes an embedded archive to a ZIP under C:\ProgramData and launches HEAVYGRAM with CreateProcessW. The Hacker News says this loader was first observed in late July 2024.

HEAVYGRAM is a Windows surveillance implant, often packaged with PyInstaller. It talks to operators over Telegram using hardcoded bot credentials. Reported capabilities include a remote shell, screenshots, browser and password theft, Telegram Desktop and WhatsApp data theft, microphone recording, and persistence.

Incoming Telegram commands are parsed by prefix. @@ runs a shell via os.popen, ** writes the message body to C:\ProgramData\ur.txt, and ## opens a backdoor suite for extra payloads, autorun keys, and Telegram Desktop theft. A background thread sends a heartbeat every 24 hours with the compromised host's domain name.

Targets in this reporting are Iranian dissidents, journalists, and opposition figures, reached through social engineering on Telegram, WhatsApp, and Instagram. The UK National Cyber Security Centre tracks related malware as CHOSEN BRICK. That label and the US HEAVYGRAM name cover overlapping activity, not two unrelated campaigns.

Related spyware and social-engineering tape includes the joint advisory on Iran's Chosen Brick spyware, how to prevent phishing attacks, and Microsoft passkey lures into Microsoft 365 theft.

If you support journalists, dissidents, or diaspora staff this week, turn on Microsoft Defender tamper protection, hunt PowerShell that adds unusual ProgramData or Telegram Desktop exclusions, and treat a Pictory, KeePass, or Telegram installer arriving in chat as hostile until a second channel confirms it.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free