Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Iran‑Linked Handala Hack Deploys HEAVYGRAM Telegram Backdoor for Credential Theft

Iran‑linked threat actor Handala Hack is leveraging a custom Telegram backdoor (HEAVYGRAM) and a Delphi utility (CRUDEEXCLUDE) to execute commands, capture screenshots and steal passwords. The incident highlights the need for continuous third‑party risk monitoring and evidentiary controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

Iran‑Linked Handala Hack Deploys HEAVYGRAM Telegram Backdoor for Credential Theft

What Happened — The threat‑actor “Handala Hack”, linked to Iranian interests, has been observed using a custom Telegram‑based backdoor named HEAVYGRAM together with a Delphi utility called CRUDEEXCLUDE. The backdoor provides remote command execution, system discovery, screenshot capture, DLL sideloading and exfiltration of Telegram session files and passwords.

Why It Matters for Trust & Control Assurance

  • Continuous third‑party risk monitoring is designed to detect unauthorized use of external communication platforms (e.g., Telegram) that can become covert data‑exfiltration channels.
  • Evidence of vendor oversight (logging, policy enforcement, and periodic review) creates a defensible audit trail when a malicious backdoor is discovered.
  • The Vendor Risk Management capability helps map this incident to a single control objective—monitor and manage third‑party service usage—which satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected — Organizations that allow employee use of Telegram or other consumer messaging apps for business communication, across all verticals (technology, finance, government, etc.).

Recommended Actions

  • Inventory all approved messaging platforms and enforce usage policies that require MFA and device‑level hardening.
  • Deploy continuous monitoring of outbound traffic to detect anomalous Telegram API calls or unknown binaries.
  • Incorporate the backdoor detection findings into your third‑party risk register and update evidence collection procedures for audit readiness. Source: The Hacker News

Technical Notes

  • Attack vector: malicious Telegram bot delivering a custom backdoor (HEAVYGRAM) and a Delphi utility (CRUDEEXCLUDE).
  • Capabilities: remote command execution, system/process discovery, screenshot capture, DLL sideloading, exfiltration of session files and stored passwords.
  • No public CVE; the threat relies on abusing Telegram’s API and user trust. Source: same as above
📰 Original Source
https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →