$ techbeacon▋
Breaches

Iran-Linked Handala Hack Connected to Telegram Backdoor HEAVYGRAM and Delphi Tool CRUDEEXCLUDE

Iran-Linked Handala Hack Connected to Telegram Backdoor HEAVYGRAM and Delphi Tool CRUDEEXCLUDE

Cybersecurity analysts have traced the activities of the self‑styled hacktivist known as Handala Hack to a sophisticated surveillance backdoor embedded in the Telegram messaging platform, identified as HEAVYGRAM, and a Delphi‑based utility called CRUDEEXCLUDE.

HEAVYGRAM is designed to run a suite of built‑in commands that enable remote code execution, system enumeration, network probing and the extraction of stored credentials. The tool can operate silently on compromised devices, leveraging Telegram’s API to receive instructions and transmit stolen data back to a command server.

The Handala Hack persona, which has previously claimed responsibility for attacks against Iranian government affiliates and dissident networks, appears to have adopted the HEAVYGRAM framework to broaden its reach. Researchers note that the combination of a messaging app’s ubiquity and a custom Delphi utility provides a flexible pipeline for infiltrating target machines and harvesting passwords.

The connection was first reported by The Hacker News, which cited technical analyses that matched code signatures and command patterns between Handala Hack’s recent payloads and the HEAVYGRAM backdoor. Independent security firms corroborated the findings, highlighting similarities in the way the malware communicates through Telegram channels and the use of CRUDEEXCLUDE to bypass common antivirus heuristics.

Experts warn that the exploitation of Telegram—a platform with over 500 million active users—poses a significant risk to individuals who rely on it for private communication, especially activists, journalists and members of diaspora communities. Because the backdoor can capture login credentials, it may be leveraged for further intrusion into email, banking and other online services.

Telegram has not issued a formal comment on the specific HEAVYGRAM module, but the company has previously emphasized its commitment to user security and the removal of malicious bots. Security researchers recommend that users enable two‑factor authentication, avoid clicking on unsolicited links, and regularly update their devices to mitigate the threat.

The discovery underscores the growing trend of state‑aligned actors repurposing mainstream communication tools for espionage. As investigators continue to dissect the malware’s architecture, authorities may pursue legal avenues to disrupt the infrastructure supporting Handala Hack and similar operations.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related