ZeroHour
Threat actor

Handala Hack

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM

Group-IB links new HEAVYGRAM and CRUDEEXCLUDE malware to Iran-aligned Handala Hack (MOIS/Void Manticore), which spies on Iranian dissidents using Defender exclusions and Telegram C2.

Group-IB documented previously unreported HEAVYGRAM and CRUDEEXCLUDE malware linked with moderate confidence to the Iran-aligned Handala Hack, assessed as a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm). CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, then a Delphi-based loader deploys a PyInstaller-packaged HEAVYGRAM implant that abuses Telegram bot APIs for command-and-control, shell execution, screenshots, audio recording, and Telegram Desktop data theft. The campaign targets Iranian dissidents, journalists, and academics with fake KeePass, Telegram, WhatsApp, and Pictory installers. The DOJ seized four related domains in March 2026 and the FBI published a HEAVYGRAM FLASH report on September 15.

GBHackers · 1h agoThreat actor in the wild 9 sources

Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware

Group-IB links HEAVYGRAM, a Telegram-based Windows surveillance backdoor targeting Iranian dissidents and journalists since 2023, to the Handala Hack group with moderate confidence.

Group-IB identified 29 additional HEAVYGRAM samples, loaders, and payloads and linked the operation to Handala Hack with moderate confidence, expanding on US government disclosures. The backdoor has targeted journalists, Iranian dissidents, and government opponents since fall 2023, including a journalist at a UK-based Farsi-language outlet and a US-based victim. It collects screenshots and audio, steals Telegram Desktop data, executes commands, and persists via Windows registry entries, with associated CRUDEEXCLUDE samples adding security exclusions before delivery.

Cyber Security Newsupdated · 1h agofirst · 2h agoMalware in the wild 9 sources