ZeroHour
GBHackerspublished ()ingested Mayura Kathir
Part of a story covered by 9 sources: “US, UK and Dutch Agencies Expose Iranian CHOSEN BRICK (HEAVYGRAM) Spyware; Group-IB Links Campaign to Handala Hack” — merged summary and timeline →

Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM

highThreat actor exploited in the wildimportance 68
AI summary · glm-5.3-flash

Group-IB links new HEAVYGRAM and CRUDEEXCLUDE malware to Iran-aligned Handala Hack (MOIS/Void Manticore), which spies on Iranian dissidents using Defender exclusions and Telegram C2.

Group-IB documented previously unreported HEAVYGRAM and CRUDEEXCLUDE malware linked with moderate confidence to the Iran-aligned Handala Hack, assessed as a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm). CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, then a Delphi-based loader deploys a PyInstaller-packaged HEAVYGRAM implant that abuses Telegram bot APIs for command-and-control, shell execution, screenshots, audio recording, and Telegram Desktop data theft. The campaign targets Iranian dissidents, journalists, and academics with fake KeePass, Telegram, WhatsApp, and Pictory installers. The DOJ seized four related domains in March 2026 and the FBI published a HEAVYGRAM FLASH report on September 15.

  • CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, preventing scanning of planted directories.
  • HEAVYGRAM is a PyInstaller-packaged Python implant using the Telegram bot API for C2, shell commands, screenshots, and data theft.
  • Lures impersonated KeePass, Telegram, WhatsApp, and Pictory installers targeting Iranian dissidents, journalists, and academics.
  • Group-IB assesses Handala Hack is a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm).
  • DOJ seized four Handala domains in March; FBI published a HEAVYGRAM FLASH report on September 15.

Indicators of compromiseAll →

TypeIndicatorContext
domainhandala-hack.toological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “
domainhandala-redwanted.tod transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “Heavygram” in incidents inv
md516602375fc2dae1eb54580ab7eda65670e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb54580ab7eda6567 Encrypted text artefact 3befcca381deb6b492aa0c4eba222c29a25
md57d3cce1f9dbaed585b61e6e903d69b9b15798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b61e6e903d69b9b Note: IP addresses and domains are intentionally defanged (
md5b2f6f40570ac9085b5463fdb623560deff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5463fdb623560de Implant/Backdoor d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637e
md5b3c1a3eebefafe1346c6a864b54231827e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346c6a864b5423182 RAR artefact 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2
sha10190940243f6535f51d43edafac943d493159e1453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346c6a864b5423182 RAR artefact 47fa634b13b8b
sha153d41445e176bf53c5acd2dad533eda612b05855ca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b61e6e903d69b9b Note: IP addresses and dom
sha188a8d118ee190ac36cf684c2992f6ddd2dda517b34b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5463fdb623560de Implant/Backdoor d2d19c7f2
sha19108466c98df01033371483a789a0c23372c52f2c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb54580ab7eda6567 Encrypted text artefact 3b
sha2563befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81f2 16602375fc2dae1eb54580ab7eda6567 Encrypted text artefact 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b
sha25647fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4943d493159e14 b3c1a3eebefafe1346c6a864b5423182 RAR artefact 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5
sha2568219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26ddst effective defense. IOCs Type SHA256 SHA1 MD5 First stage 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346
sha256d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377ed2dda517b b2f6f40570ac9085b5463fdb623560de Implant/Backdoor d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb5
Full article916 words · extracted from gbhackers.com · click to collapse

A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation.

The campaign combines targeted social engineering, Microsoft Defender exclusion abuse, multi-stage loaders, and Telegram-based command-and-control to surveil Iranian dissidents, journalists, and people perceived as opponents of the Iranian government.

The research expands on U.S. government disclosures issued earlier this year. On March 19, the U.S.

Department of Justice seized four domains it said were used by Iran’s Ministry of Intelligence and Security (MOIS) to support cyber-enabled psychological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to.

The DOJ affidavit described “Heavygram” in incidents involving victims contacted through Telegram and tricked into executing malware disguised as legitimate software.

The FBI subsequently published an expanded HEAVYGRAM FLASH report on September 15, detailing a Windows-focused surveillance toolkit that uses Telegram bots, groups, and user accounts as command-and-control infrastructure.

UK and Dutch authorities track the activity under the name CHOSEN BRICK, while the FBI attributes HEAVYGRAM operations to actors working for MOIS.

These Delphi-based samples display convincing graphical interfaces while silently unpacking embedded archives and launching HEAVYGRAM’s persistent implant.

A core feature is defense evasion. CRUDEEXCLUDE uses PowerShell to add attacker-controlled locations to Microsoft Defender exclusions, preventing files written to those paths from being scanned.

Observed exclusions include directories resembling legitimate Windows or application locations, such as %ALLUSERSPROFILE%\MicrosoftDistribution\sysmain, C:\Users\<username>\Downloads\Telegram Desktop, and %ALLUSERSPROFILE%\SMQDServicePackages\488ht1-8ww648q.

The malware decodes an embedded payload, saves it as a ZIP archive, extracts it into C:\ProgramData, and launches the HEAVYGRAM binary with CreateProcessW.

This approach gives the operators a reliable route to install their surveillance implant after weakening local endpoint protections.

The use of fake applications is particularly effective against high-risk targets who may expect to receive messaging, password-management, or media-related software.


HEAVYGRAM killchain (Source : GroupIB).
HEAVYGRAM killchain (Source : GroupIB).

Earlier delivery lures impersonated KeePass, Telegram, WhatsApp, and Pictory installers, while a Persian-language screensaver lure referenced a “supplementary and expelled list,” indicating targeting tailored to academics or students.

HEAVYGRAM’s second-stage implant is a PyInstaller-packaged Python executable built for persistence and remote access on Windows.

Group-IB identified CRUDEEXCLUDE, executables masquerading as trusted programs such as Pictory and Telegram.

It creates a mutex to avoid duplicate execution, writes configuration data under %APPDATA%\Config\config.xml, collects the compromised host’s name, and uses hardcoded Telegram bot credentials and group or user identifiers to communicate with operators.

HEAVYGRAM Malware Deployment

The implant sends an initial beacon and periodic health checks over Telegram, allowing operators to identify active machines without maintaining conventional malicious infrastructure.

It can receive textual commands and file attachments through Telegram’s bot API, making detection more difficult because the traffic blends with a widely used legitimate cloud messaging service.

Commands include arbitrary shell execution through os.popen, process enumeration, public IP discovery, system-information collection, screenshot capture, payload deployment, registry-based persistence, and theft of Telegram Desktop data.

HEAVYGRAM can also download and execute additional executables, unpack ZIP-delivered payloads, and use DLL side-loading by copying the legitimate bthudtask.exe binary into the spoofed C:\Windows \SysWOW64 directory, which contains an intentional trailing space.

Public reporting on the FBI advisory further indicates that variants can collect browser-stored communications and credentials, record audio, delete files, and retrieve additional malware.

Indicators include suspicious Run key persistence entries such as SMQDService or winappx, unexpected Telegram API connections, and the anomalous C:\Windows \SysWOW64 path.

Group-IB assesses that Handala Hack is not an independent hacktivist group, but an online persona associated with Void Manticore, also tracked as Storm-0842, Banished Kitten, and Red Sandstorm.

March 19 2026 affidavit (Source : GroupIB).
 March 19 2026 affidavit (Source : GroupIB).

The operation has portrayed itself as a cyber-resistance movement, yet its target selection, infrastructure, destructive activity, leaks, intimidation, and alignment with Iranian state interests are consistent with a MOIS-linked coercive campaign.

The latest disclosures reinforce that the operation’s purpose extends beyond espionage.

A number of Delphi-based executables have also been identified which masquerade as legitimate applications such as Pictory and Telegram.

Access to victim systems and messaging accounts can support surveillance, public exposure, hack-and-leak operations, intimidation, and the identification of opposition figures.

Masquerading applications (Source : GroupIB).
Masquerading applications (Source : GroupIB).

The DOJ said the seized MOIS-linked sites had been used to claim responsibility for intrusions, publish stolen data, and call for violence against journalists, dissidents, and Israeli individuals.

Defenders should investigate PowerShell activity that modifies Defender exclusions, particularly when exclusions point to unusual ProgramData, download, or misspelled service directories.

They should also hunt for registry persistence involving SMQDService and winappx, examine executions of fake KeePass, Telegram, or Pictory installers, and monitor unusual outbound requests to api.telegram.org originating from endpoints that do not normally automate Telegram activity.

Organizations supporting journalists, activists, researchers, and diaspora communities should prioritize application allowlisting, Microsoft Defender tamper protection, phishing-resistant MFA, endpoint telemetry, and strict verification of software received through messaging platforms.

The campaign begins with trust-based contact and a convincing decoy; preventing the initial execution remains the most effective defense.

IOCs

TypeSHA256SHA1MD5
First stage8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd0190940243f6535f51d43edafac943d493159e14b3c1a3eebefafe1346c6a864b5423182
RAR artefact47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de488a8d118ee190ac36cf684c2992f6ddd2dda517bb2f6f40570ac9085b5463fdb623560de
Implant/Backdoord2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e9108466c98df01033371483a789a0c23372c52f216602375fc2dae1eb54580ab7eda6567
Encrypted text artefact3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e8153d41445e176bf53c5acd2dad533eda612b058557d3cce1f9dbaed585b61e6e903d69b9b

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/heavygram-malware-deployment/