Executive Summary
The Iran-linked 'hacktivist' persona Handala Hack, attributed with moderate confidence to the MOIS-affiliated actor Void Manticore (also known as Red Sandstorm), has been linked to a sophisticated surveillance campaign active since Fall 2023. The campaign utilizes a Python-based backdoor dubbed HEAVYGRAM (or CHOSEN BRICK) and a Delphi-based loader named CRUDEEXCLUDE to conduct intelligence collection and hack-and-leak operations.
The attack chain typically begins with social engineering via messaging platforms, delivering malware masquerading as legitimate installers like Telegram, KeePass, or Pictory. Technically, the malware leverages the Telegram Bot API for command-and-control (C2), enabling remote command execution, file exfiltration (specifically Telegram session data), and persistent surveillance through screenshots and audio recording.
This activity is high-impact, specifically targeting Iranian dissidents, journalists, and government opposition groups. The threat actor converts stolen data into public exposure and intimidation, serving as a coercive arm of the Iranian state under a hacktivist guise. Organizations in media, government, and dissident support circles should prioritize defenses against these Telegram-based surveillance tools.
Key Details
Threat Name
HEAVYGRAM Telegram Backdoor
Affects
—
Adversary
Handala Hack Other Adversaries and Aliases: Void Manticore; Red Sandstorm
MITRE Techniques
Malware/Tools
HEAVYGRAM, CRUDEEXCLUDE, SHADEGENES, Roadsweep, ZeroCleare, ChimneySweep, Rhadamanthys Stealer, Remcos, Mimikatz
