TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #994 635
🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CRUDEEXCLUDE malware families, expanding our understanding of activity attributed with moderate confidence to Handala Hack.

The investigation reveals a multi-stage Windows infection chain combining social engineering, legitimate application masquerading, PowerShell execution, Defender exclusions and persistent access.

At the centre of the operation is HEAVYGRAM, a Python-based Windows backdoor that uses Telegram’s Bot API for C2 and data exfiltration. Operators can remotely execute commands, capture screenshots, collect system and process information, steal Telegram session data and deploy additional payloads.

The research also shows how CRUDEEXCLUDE is used to prepare compromised systems by adding paths to Microsoft Defender exclusions before deploying subsequent stages.

Read the full technical analysis.

#ThreatIntelligence #HandalaHack #HEAVYGRAM
  • 🔥 8
  • 👍 2
  • ❤ 1
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  3. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  4. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  5. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
  6. Aug 27, 2026🚨 By the time a bank detects fraud, legacy systems are simply watching the end of a story…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →