$ techbeacon▋
Malware

Iran‑linked Handala Hack leverages new “CRUDEEXCLUDE” tool to bypass Microsoft Defender and drop novel “HEAVYGRAM” payload

Iran‑linked Handala Hack leverages new “CRUDEEXCLUDE” tool to bypass Microsoft Defender and drop novel “HEAVYGRAM” payload

Security researchers have identified a previously unknown malware family, dubbed HEAVYGRAM, being delivered by the Iran‑aligned Handala Hack operation. The campaign, first reported by the independent group GBHackers, uses a custom utility called CRUDEEXCLUDE to manipulate Microsoft Defender’s exclusion settings, effectively turning off key protective functions before the main payload is installed.

The attack chain begins with targeted social‑engineering messages that lure victims into opening malicious documents or links. Once executed, a lightweight loader drops CRUDEEXCLUDE, which edits the Defender configuration to add specific file paths and processes to the exclusion list. By doing so, the subsequent stages of the malware—particularly the HEAVYGRAM payload—can run unchecked, evading detection by one of Windows’ primary security layers.

HEAVYGRAM itself is a multi‑stage loader that fetches additional components from remote servers, often using encrypted communications over Telegram channels. This use of Telegram aligns with a pattern observed in several state‑aligned threat groups that prefer the platform’s end‑to‑end encryption and ease of rapid command‑and‑control distribution. The final stage of the infection can install a range of capabilities, from credential theft to lateral movement tools, although the exact functional modules vary between samples.

Analysts assigning moderate confidence to the attribution note that the code shares markers with prior Handala Hack operations, including specific obfuscation techniques and language strings in Persian. While the HEAVYGRAM and CRUDEEXCLUDE families have not been catalogued in major malware repositories before, their emergence underscores a growing trend of threat actors targeting built‑in security products to create blind spots for their malicious code.

Microsoft has not issued a dedicated advisory on the CRUDEEXCLUDE technique, but the company routinely updates Defender to recognize abnormal exclusion modifications. Security experts recommend that organizations monitor changes to exclusion lists and enforce strict policies that limit who can alter Defender settings, especially on endpoints that handle sensitive data.

The discovery highlights the evolving sophistication of cyber‑espionage groups that blend social engineering, legitimate tool abuse, and encrypted messaging platforms. As defenders adapt, continued threat‑intel sharing and rapid patching remain essential to mitigate the risk posed by these emerging tools.

Source: GBHackers
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related