Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Group-IB attributes the Iran-linked hacktivist persona Handala (Void Manticore/MOIS) to the Telegram-based HEAVYGRAM backdoor and CRUDEEXCLUDE staging utility.
Group-IB links the Iran-aligned hacktivist persona Handala Hack, assessed as Void Manticore (aka Storm-0842) affiliated with Iran's Ministry of Intelligence and Security, to the Python-based HEAVYGRAM backdoor and the Delphi staging utility CRUDEEXCLUDE. HEAVYGRAM, first detected in the wild in September 2023, uses Telegram bots for encrypted C2 with prefix-delimited commands, supporting remote execution, screenshots, password and browser theft, and Telegram session file exfiltration, while persisting via autorun registry keys and adding Microsoft Defender exclusions. Infection chains start with social engineering on Telegram, WhatsApp and Instagram, delivering malware disguised as Pictory, KeePass or Telegram installers via WSF/VBS scripts, HTA files or embedded archives. The FBI has tied the campaign to MOIS targeting dissidents and journalists, and the UK NCSC tracks the same family as CHOSEN BRICK.