Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
Group-IB links new HEAVYGRAM and CRUDEEXCLUDE malware to Iran-aligned Handala Hack (MOIS/Void Manticore), which spies on Iranian dissidents using Defender exclusions and Telegram C2.
Group-IB documented previously unreported HEAVYGRAM and CRUDEEXCLUDE malware linked with moderate confidence to the Iran-aligned Handala Hack, assessed as a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm). CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, then a Delphi-based loader deploys a PyInstaller-packaged HEAVYGRAM implant that abuses Telegram bot APIs for command-and-control, shell execution, screenshots, audio recording, and Telegram Desktop data theft. The campaign targets Iranian dissidents, journalists, and academics with fake KeePass, Telegram, WhatsApp, and Pictory installers. The DOJ seized four related domains in March 2026 and the FBI published a HEAVYGRAM FLASH report on September 15.
- CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, preventing scanning of planted directories.
- HEAVYGRAM is a PyInstaller-packaged Python implant using the Telegram bot API for C2, shell commands, screenshots, and data theft.
- Lures impersonated KeePass, Telegram, WhatsApp, and Pictory installers targeting Iranian dissidents, journalists, and academics.
- Group-IB assesses Handala Hack is a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm).
- DOJ seized four Handala domains in March; FBI published a HEAVYGRAM FLASH report on September 15.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | handala-hack.to | ological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “ |
| domain | handala-redwanted.to | d transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “Heavygram” in incidents inv |
| md5 | 16602375fc2dae1eb54580ab7eda6567 | 0e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb54580ab7eda6567 Encrypted text artefact 3befcca381deb6b492aa0c4eba222c29a25 |
| md5 | 7d3cce1f9dbaed585b61e6e903d69b9b | 15798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b61e6e903d69b9b Note: IP addresses and domains are intentionally defanged ( |
| md5 | b2f6f40570ac9085b5463fdb623560de | ff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5463fdb623560de Implant/Backdoor d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637e |
| md5 | b3c1a3eebefafe1346c6a864b5423182 | 7e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346c6a864b5423182 RAR artefact 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2 |
| sha1 | 0190940243f6535f51d43edafac943d493159e14 | 53084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346c6a864b5423182 RAR artefact 47fa634b13b8b |
| sha1 | 53d41445e176bf53c5acd2dad533eda612b05855 | ca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b61e6e903d69b9b Note: IP addresses and dom |
| sha1 | 88a8d118ee190ac36cf684c2992f6ddd2dda517b | 34b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5463fdb623560de Implant/Backdoor d2d19c7f2 |
| sha1 | 9108466c98df01033371483a789a0c23372c52f2 | c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb54580ab7eda6567 Encrypted text artefact 3b |
| sha256 | 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 | f2 16602375fc2dae1eb54580ab7eda6567 Encrypted text artefact 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b |
| sha256 | 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 | 943d493159e14 b3c1a3eebefafe1346c6a864b5423182 RAR artefact 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5 |
| sha256 | 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd | st effective defense. IOCs Type SHA256 SHA1 MD5 First stage 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346 |
| sha256 | d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e | d2dda517b b2f6f40570ac9085b5463fdb623560de Implant/Backdoor d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb5 |
Full article916 words · extracted from gbhackers.com · click to collapse
A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation.
The campaign combines targeted social engineering, Microsoft Defender exclusion abuse, multi-stage loaders, and Telegram-based command-and-control to surveil Iranian dissidents, journalists, and people perceived as opponents of the Iranian government.
The research expands on U.S. government disclosures issued earlier this year. On March 19, the U.S.
Department of Justice seized four domains it said were used by Iran’s Ministry of Intelligence and Security (MOIS) to support cyber-enabled psychological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to.
The DOJ affidavit described “Heavygram” in incidents involving victims contacted through Telegram and tricked into executing malware disguised as legitimate software.
The FBI subsequently published an expanded HEAVYGRAM FLASH report on September 15, detailing a Windows-focused surveillance toolkit that uses Telegram bots, groups, and user accounts as command-and-control infrastructure.
UK and Dutch authorities track the activity under the name CHOSEN BRICK, while the FBI attributes HEAVYGRAM operations to actors working for MOIS.
These Delphi-based samples display convincing graphical interfaces while silently unpacking embedded archives and launching HEAVYGRAM’s persistent implant.
A core feature is defense evasion. CRUDEEXCLUDE uses PowerShell to add attacker-controlled locations to Microsoft Defender exclusions, preventing files written to those paths from being scanned.
Observed exclusions include directories resembling legitimate Windows or application locations, such as %ALLUSERSPROFILE%\MicrosoftDistribution\sysmain, C:\Users\<username>\Downloads\Telegram Desktop, and %ALLUSERSPROFILE%\SMQDServicePackages\488ht1-8ww648q.
The malware decodes an embedded payload, saves it as a ZIP archive, extracts it into C:\ProgramData, and launches the HEAVYGRAM binary with CreateProcessW.
This approach gives the operators a reliable route to install their surveillance implant after weakening local endpoint protections.
The use of fake applications is particularly effective against high-risk targets who may expect to receive messaging, password-management, or media-related software.

Earlier delivery lures impersonated KeePass, Telegram, WhatsApp, and Pictory installers, while a Persian-language screensaver lure referenced a “supplementary and expelled list,” indicating targeting tailored to academics or students.
HEAVYGRAM’s second-stage implant is a PyInstaller-packaged Python executable built for persistence and remote access on Windows.
Group-IB identified CRUDEEXCLUDE, executables masquerading as trusted programs such as Pictory and Telegram.
It creates a mutex to avoid duplicate execution, writes configuration data under %APPDATA%\Config\config.xml, collects the compromised host’s name, and uses hardcoded Telegram bot credentials and group or user identifiers to communicate with operators.
HEAVYGRAM Malware Deployment
The implant sends an initial beacon and periodic health checks over Telegram, allowing operators to identify active machines without maintaining conventional malicious infrastructure.
It can receive textual commands and file attachments through Telegram’s bot API, making detection more difficult because the traffic blends with a widely used legitimate cloud messaging service.
Commands include arbitrary shell execution through os.popen, process enumeration, public IP discovery, system-information collection, screenshot capture, payload deployment, registry-based persistence, and theft of Telegram Desktop data.
HEAVYGRAM can also download and execute additional executables, unpack ZIP-delivered payloads, and use DLL side-loading by copying the legitimate bthudtask.exe binary into the spoofed C:\Windows \SysWOW64 directory, which contains an intentional trailing space.
Public reporting on the FBI advisory further indicates that variants can collect browser-stored communications and credentials, record audio, delete files, and retrieve additional malware.
Indicators include suspicious Run key persistence entries such as SMQDService or winappx, unexpected Telegram API connections, and the anomalous C:\Windows \SysWOW64 path.
Group-IB assesses that Handala Hack is not an independent hacktivist group, but an online persona associated with Void Manticore, also tracked as Storm-0842, Banished Kitten, and Red Sandstorm.

The operation has portrayed itself as a cyber-resistance movement, yet its target selection, infrastructure, destructive activity, leaks, intimidation, and alignment with Iranian state interests are consistent with a MOIS-linked coercive campaign.
The latest disclosures reinforce that the operation’s purpose extends beyond espionage.
A number of Delphi-based executables have also been identified which masquerade as legitimate applications such as Pictory and Telegram.
Access to victim systems and messaging accounts can support surveillance, public exposure, hack-and-leak operations, intimidation, and the identification of opposition figures.

The DOJ said the seized MOIS-linked sites had been used to claim responsibility for intrusions, publish stolen data, and call for violence against journalists, dissidents, and Israeli individuals.
Defenders should investigate PowerShell activity that modifies Defender exclusions, particularly when exclusions point to unusual ProgramData, download, or misspelled service directories.
They should also hunt for registry persistence involving SMQDService and winappx, examine executions of fake KeePass, Telegram, or Pictory installers, and monitor unusual outbound requests to api.telegram.org originating from endpoints that do not normally automate Telegram activity.
Organizations supporting journalists, activists, researchers, and diaspora communities should prioritize application allowlisting, Microsoft Defender tamper protection, phishing-resistant MFA, endpoint telemetry, and strict verification of software received through messaging platforms.
The campaign begins with trust-based contact and a convincing decoy; preventing the initial execution remains the most effective defense.
IOCs
| Type | SHA256 | SHA1 | MD5 |
| First stage | 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd | 0190940243f6535f51d43edafac943d493159e14 | b3c1a3eebefafe1346c6a864b5423182 |
| RAR artefact | 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 | 88a8d118ee190ac36cf684c2992f6ddd2dda517b | b2f6f40570ac9085b5463fdb623560de |
| Implant/Backdoor | d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e | 9108466c98df01033371483a789a0c23372c52f2 | 16602375fc2dae1eb54580ab7eda6567 |
| Encrypted text artefact | 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 | 53d41445e176bf53c5acd2dad533eda612b05855 | 7d3cce1f9dbaed585b61e6e903d69b9b |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/heavygram-malware-deployment/