Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Overview
Researchers have linked the Iranian hacktivist group Handala Hack to a new surveillance tool called HEAVYGRAM, which operates through Telegram. This backdoor allows attackers to execute commands remotely, collect system and network information, and even capture screenshots. Additionally, there's a Delphi-based utility named CRUDEEXCLUDE involved. These tools can exfiltrate sensitive data, including passwords and Telegram session files, raising significant concerns for users of these platforms. The implications are serious, as the use of such tools could lead to widespread data breaches and privacy violations, especially for individuals and organizations utilizing Telegram for communication.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Telegram users, particularly those targeted by Iranian hacktivists
- Action Required: Users should enhance their security practices on Telegram, including using two-factor authentication and being cautious about suspicious links or messages.
- Timeline: Newly disclosed
Original Article Summary
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
Impact
Telegram users, particularly those targeted by Iranian hacktivists
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should enhance their security practices on Telegram, including using two-factor authentication and being cautious about suspicious links or messages.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.