HEAVYGRAM Telegram Backdoor Used by Handala Hack
Score: 8/10

HEAVYGRAM Telegram Backdoor Used by Handala Hack

The Iran-linked threat actor Handala Hack uses the HEAVYGRAM Telegram-based backdoor and CRUDEEXCLUDE utility to target dissidents and journalists for surveillance and data exfiltration.

Executive Summary

The Iran-linked 'hacktivist' persona Handala Hack, attributed with moderate confidence to the MOIS-affiliated actor Void Manticore (also known as Red Sandstorm), has been linked to a sophisticated surveillance campaign active since Fall 2023. The campaign utilizes a Python-based backdoor dubbed HEAVYGRAM (or CHOSEN BRICK) and a Delphi-based loader named CRUDEEXCLUDE to conduct intelligence collection and hack-and-leak operations.

The attack chain typically begins with social engineering via messaging platforms, delivering malware masquerading as legitimate installers like Telegram, KeePass, or Pictory. Technically, the malware leverages the Telegram Bot API for command-and-control (C2), enabling remote command execution, file exfiltration (specifically Telegram session data), and persistent surveillance through screenshots and audio recording.

This activity is high-impact, specifically targeting Iranian dissidents, journalists, and government opposition groups. The threat actor converts stolen data into public exposure and intimidation, serving as a coercive arm of the Iranian state under a hacktivist guise. Organizations in media, government, and dissident support circles should prioritize defenses against these Telegram-based surveillance tools.

Key Details

Threat Name

HEAVYGRAM Telegram Backdoor

Affects

—

Adversary

Handala Hack Other Adversaries and Aliases: Void Manticore; Red Sandstorm

Malware/Tools

HEAVYGRAM, CRUDEEXCLUDE, SHADEGENES, Roadsweep, ZeroCleare, ChimneySweep, Rhadamanthys Stealer, Remcos, Mimikatz

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance7
Clarity & Structure9
Technical Depth8

Sources