The images in this article were generated with artificial intelligence. How we publish
Security investigators have identified a chain of attack associated with the online person known as Handala Hack and a set of tools using Telegram as a command and control channel. According to public reports from the firm Group-IB and notices from the FBI and other agencies, the campaign uses a Python-based backdoor called HEAVYGRAM and an environment installer or prepper written in Delphi called CRUDEEXCLADE; both have been used to infiltrate Windows equipment and maintain persistent access to selected victims.
Confirmed facts: Group-IB documented HEAVYGRAM's capabilities, including file exfiltration and messaging application sessions, screen capture, microphone activation, remote command execution, DLL sideloading and persistence by autorun keys in Windows registry. CRUDEEXCLUDE acts as a pre-stage to create staging directories and modify Microsoft Defender exclusions; Google described similar samples used for that purpose. Several public agencies - including the FBI and the UK NCSC - have noted that the operators have led these operations against Iranian dissidents, critical journalists with Iran and opposition groups, with intelligence collection objectives and "hack and leak" campaigns. For general information on risks and state actors linked to Iran, see official pages such as the FBI and Group-IB: https: / / www.fbi.gov / investigate / cyber and https: / / www.group-ib.com /.

How it works technically (reconstructed explanation from the findings): attackers contact the victim by Telegram, WhatsApp or Instagram using social engineering - offering technical support, pretending to be reliable contacts or sending "useful" installers with graphic interface. The installer (often packaged to look like Pictory, KeePass, Telegram or another legitimate app) contains the second stage: HEAVYGRAM or compressed files that CRUDEEXCLES decompress on staging routes. CRUDEEXCLO has also been observed by setting exclusions in Microsoft Defender, which prevents the scanning of the folders where the payloads are placed.
In the committed teams HEAVYGRAM establishes C2 communication through a Telegram bot. The malware processes incoming commands with specific prefixes (e.g., @ @ to run system commands, * * to write content in C:\\ ProgramData\\ ur.txt, and secondary to update tokens or install the Trojan in autorun keys). In addition to running arbitrary code, you can list processes, take screenshots, flip cookies and passwords saved by browsers, collect data from messaging applications and transfer files to and from the operator. The implant also sends an initial "beacon" with the host domain name and a beat every 24 hours to confirm activity.
Those who are affected and why it matters: the main objective are individuals and organizations of interest to the Iranian State: critical journalists, activists and dissidents. The real risk includes loss of privacy (capture, audio, messages), public exposure of sensitive information (doxxing), account commitments and reputational damage; in addition, actors linked to Handala / the associated alias have precedents of data erasing and filtering operations, so there is also risk of removal or malicious publication of information if access to critical files is achieved.
Differentiating facts and estimates: it is a fact that the analyzed samples exhibit the functions described and that messaging channels are used for social-engineering and C2. The attribution to Iranian intelligence (MOIS) and to operators known as Void Manticore / Handala Hack comes from evaluations of agencies and signatures - it is a conclusion with a high level of confidence for these entities, but, as in all attribution, it is not an "absolute certainty" public: the response community treats this as an assessment based on evidence of infrastructure, techniques and objectives. Another less clear area that remains under review is the degree of automation and whether there are variants using other C2 services outside Telegram.
Practical consequences for users and organizations: in addition to the direct risk to target people, the extensive use of Telegram as C2 and avoidance techniques (defense exclusions, autoruns, sideloading) stresses that even legitimate software downloaded from messages can be a vector if it has been manipulated to carry malicious loads. For companies with employees dealing with sensitive issues - journalists, NGOs, media, universities - intrusions can lead to internal leaks, extortion or reputational damage.
Specific measures to be taken by the reader now (immediate and verifiable actions): 1) Do not run installers received by messaging without checking the sender and the digital signature of the installer. 2) Review exclusions in Microsoft Defender with PowerShell (Get-MpPreference) and remove any suspicious route; also check autorun keys in HKLM / HKCU\\ Software\\ Microsoft\ Windows\\ Current Version\\ Run and unauthorised scheduled tasks. 3) Examine C:\\ ProgramData and search for atypical files or the C file:\\ ProgramData\\ ur.txt if it appears in your system; if you find suspicious artifacts isolate the network machine. 4) Rotate passwords on unreliable equipment and force application session closure (Telegram Desktop, WhatsApp Web) and revoke tokens; activate multifactor authentication in key services. 5) Keep offline backup and verify integrity before restoring. 6) If there are signs of commitment (unknown executions, new services, recent screenshots), contact an incident response team or trusted suppliers and consider forensic image for evidence preservation.

Institutional and policy mitigation measures: organisations that manage high-risk objectives should adopt strict endpoints management rules (limiting software installation by policy, applying white lists, EDR with telemetry, blocking the execution of macros and scripts from unreliable locations) and training staff in social networking practices. It is also recommended that media groups and NGOs work with legal and security equipment for filtering and doxxing protocols.
What remains uncertain and why continue to monitor: it is clear that the campaign is multistage and flexible; however, the exact prevalence in different regions and the speed of rotation of C2 infrastructure (bots and groups in Telegram) change over time, so tactical indicators can expire quickly. Defenses should focus on principles of digital hygiene and behaviour-based detection rather than static signatures.
Summary in one sentence: HEAVYGRAM and CRUDEEXCLUDE represent an operational tool that combines social engineering in messaging, antivirus evasion and Telegram communication to infiltrate sensitive objectives; effective defense requires strict verification of installers, review of security exclusions and rapid response procedures. For best practice resources and technical guides on intrusion response and endpoints protection, please consult Microsoft Defender and national security agencies such as NCSC: https: / / learn.microsoft.com / microsoft-365 / security / defender-endpoint / and https: / / www.ncsc.gov.uk /.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...