#Heavygram
イラン関連のHandala Hackグループ、パスワード窃取可能なTelegram バックドアHEAVYGRAM使用

イラン関連のHandala Hackグループが、Telegram経由で動作するバックドアHEAVYGRAMを使用。パスワード、メッセージデータ、スクリーンショット、ファイルの窃取が可能。対象組織は影響評価を急ぐ必要がある。

#マルウェア #情報セキュリティ
イラン関連のHandala Hackグループ、パスワード窃取可能なTelegram バックドアHEAVYGRAM使用
イラン関連のHandala Hackグループが、Telegram経由で動作するバックドアHEAVYGRAMを使用。パスワード、メッセージデータ、スクリーンショット、ファイルの窃取が可能。対象組織は影響評価を急ぐ必要がある。
thehackernews.com
September 21, 2026 at 12:01 PM
Iran-linked hacktivist Handala Hack is tied to the Telegram backdoor HEAVYGRAM and Delphi utility CRUDEEXCLUDE. HEAVYGRAM supports remote commands, info discovery, exfiltration, and more.
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Handala Hack is linked to HEAVYGRAM, a Telegram-based backdoor that can steal passwords, messaging data, screenshots, and files.
thehackernews.com
September 20, 2026 at 3:33 PM
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords thehackernews.com/2026/09/iran...
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Handala Hack is linked to HEAVYGRAM, a Telegram-based backdoor that can steal passwords, messaging data, screenshots, and files.
thehackernews.com
September 20, 2026 at 8:42 AM
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
www.group-ib.com
September 19, 2026 at 2:24 PM
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.

"HEAV…
#hackernews #news
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
thehackernews.com
September 18, 2026 at 3:21 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

Leer Más / Read More...
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Haz clic para acceder al contenido completo.
thehackernews.com
September 18, 2026 at 6:31 AM
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 18, 2026 at 5:27 AM
HEAVYGRAM and CRUDEEXCLUDE enable Telegram-based intrusion, discovery, exfiltration, persistence, and defense evasion tied to Iran-linked hacktivist activity.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 18, 2026 at 5:05 AM
HEAVYGRAM and CRUDEEXCLUDE enable Telegram-based intrusion, discovery, exfiltration, persistence, and defense evasion tied to Iran-linked hacktivist activity.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 18, 2026 at 5:03 AM
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords: thehackernews.com/2026/09/iran...
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Handala Hack is linked to HEAVYGRAM, a Telegram-based backdoor that can steal passwords, messaging data, screenshots, and files.
thehackernews.com
September 17, 2026 at 10:58 PM
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

The narrative demonstrates a sophisticated convergence of state-sponsored operational objectives with readily available, low-overhead C2 infrastructure, primarily leveraging the Telegram ecosystem. Th…
huntaegis.com
September 17, 2026 at 4:15 PM
DIQQAT! HEAVYGRAM: Telegram orqali boshqariluvchi josuslik zararli dasturi sizning ham qurilmangizda bo‘lishi mumkin!

The strongest version of this narrative is a technical warning about the "living-off-the-land" evolution of malware, where attackers leverage trusted third-party platforms to hi…
huntaegis.com
September 17, 2026 at 3:36 PM
Handala Hackが「CRUDEEXCLUDE」でDefenderの保護機能を無効化し「HEAVYGRAM」を展開

イラン寄りのHandala Hack作戦と中程度の確信度で関連付けられる、これまで報告されていなかったマルウェア「HEAVYGRAM」および「CRUDEEXCLUDE」のサンプルが確認されました。アンチマルウェアソフトウェア このキャンペーンは、標的型ソーシャルエンジニアリング、Microsoft Defenderの
Handala Hackが「CRUDEEXCLUDE」でDefenderの保護機能を無効化し「HEAVYGRAM」を展開
イラン寄りのHandala Hack作戦と中程度の確信度で関連付けられる、これまで報告されていなかったマルウェア「HEAVYGRAM」および「CRUDEEXCLUDE」のサンプルが確認されました。アンチマルウェアソフトウェア このキャンペーンは、標的型ソーシャルエンジニアリング、Microsoft Defenderの
blackhatnews.tokyo
September 17, 2026 at 1:56 PM
September 17, 2026 at 1:39 PM
Nieuwe malware genaamd HEAVYGRAM gebruikt Telegram voor surveillance.

De nieuw ontdekte surveillance-malware, HEAVYGRAM genaamd, maakt effectief gebruik van de populaire berichtenapp Telegram als commandocentrum. Dit elimineert de noodzaak voor aparte communicatieservers. De malw...
Nieuwe malware genaamd HEAVYGRAM gebruikt Telegram voor surveillance.
De nieuw ontdekte surveillance-malware, HEAVYGRAM genaamd, maakt effectief gebruik van de populaire berichtenapp Telegram als commandocentrum. Dit elimineert de noodzaak voor aparte communicatieservers. De malware, die sinds de herfst van 2023 wordt ingezet, richt zich op journalisten, Iraanse dissidenten en personen die kritisch staan tegenover de Iraanse regering. Het onderzoek koppelt HEAVYGRAM aan een campagne gericht op personen van belang voor Iran, waaronder een journalist bij een in het VK gevestigd Farsi-taal nieuwsmedium en een slachtoffer in de VS. HEAVYGRAM communiceert via Telegram bots, accounts en groepen. Aanvallers versturen instructies en ontvangen gestolen data, en kunn...
newsfacts.info
September 17, 2026 at 1:01 PM
Iranian state spyware hides in fake Telegram/WhatsApp app installs - and can fully wipe your device. https://intel.threadlinqs.com/threat/TL-2026-2543 #ThreatIntel #CHOSEN #HEAVYGRAM #telegram
September 17, 2026 at 2:58 AM
Iran's MOIS runs spyware C2 through Telegram, one bot per victim.
Per-victim C2 breaks indicator-based blocking and hides in traffic you already allow.
#ThreatIntel #ICS #CyberSecurity
https://threat-intelligence.redeyesecurity.com/blog/iran-mois-heavygram-chosen-brick-telegram-malware-2026
September 16, 2026 at 8:06 PM