17-09-2026
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2/
Report completeness: High
Actors/Campaigns:
Handala-hacking-team (motivation: hacktivism)
Threats:
Heavygram
Crudeexclude
Dll_sideloading_technique
Victims:
Iranian dissidents, Journalists, Government opponents, Media sector
Industry:
Government, Military
Geo:
Iran, Germany, London, Israel, Palestinian, Iranian, United states, Albania, Israeli, United kingdom, Bahrain
TTPs:
Tactics: 1
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1027, T1027.009, T1036, T1036.005, T1041, T1059, T1059.001, T1059.005, T1070.004, T1071.001, have more...
IOCs:
Domain: 4
File: 20
Url: 9
Path: 1
Hash: 41
Soft:
Telegram, Windows remote desktop, KeePass, Windows registry, PyInstaller
Algorithms:
base64, zip, exhibit
Functions:
Get-BotUpdates
Win API:
lockfile, GetEnvironmentVariableW, CreateProcessW
Win Services:
WebClient
Languages:
powershell, python, vbscript, delphi