🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CRUDEEXCLUDE malware families, expanding our understanding of activity attributed with moderate confidence to Handala Hack.
The investigation reveals a multi-stage Windows infection chain combining social engineering, legitimate application masquerading, PowerShell execution, Defender exclusions and persistent access.
At the centre of the operation is HEAVYGRAM, a Python-based Windows backdoor that uses Telegram’s Bot API for C2 and data exfiltration. Operators can remotely execute commands, capture screenshots, collect system and process information, steal Telegram session data and deploy additional payloads.
The research also shows how CRUDEEXCLUDE is used to prepare compromised systems by adding paths to Microsoft Defender exclusions before deploying subsequent stages.
Read the full technical analysis.
#ThreatIntelligence #HandalaHack #HEAVYGRAM
Post #994
635

- 🔥 8
- 👍 2
- ❤ 1