Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Affiliated Hackers Exploit Telegram for Data Breaches

Iran-Affiliated Hackers Exploit Telegram for Data Breaches

Posted on September 18, 2026 By CWS

The cyber landscape has been shaken by the discovery of an Iran-linked hacking group known as Handala Hack, exploiting Telegram for cyber espionage. Utilizing a sophisticated backdoor named HEAVYGRAM, these hackers are targeting dissidents and journalists, posing significant cybersecurity threats.

Unveiling the HEAVYGRAM Backdoor

HEAVYGRAM, a Telegram-based surveillance tool, offers various capabilities to infiltrate targeted systems. Its features include remote command execution, data exfiltration, and system reconnaissance. Group-IB reveals that it can capture screenshots, manipulate DLLs, and maintain persistence using Windows autorun keys.

In conjunction with HEAVYGRAM, the Delphi-based CRUDEEXCLUDE utility prepares the environment for malware deployment. Detected initially in July 2024, CRUDEEXCLUDE masquerades as a legitimate application while configuring Microsoft Defender to evade detection.

Targeted Cyber Operations

The U.S. FBI has raised alarms over these operations, attributing them to Iranian cyber actors acting on behalf of the Ministry of Intelligence and Security (MOIS). The primary targets include Iranian dissidents and opposition journalists, aiming to collect intelligence and damage reputations.

Social engineering tactics are a hallmark of these attacks. Hackers use messaging platforms such as Telegram, WhatsApp, and Instagram to lure targets with the guise of technical support or trusted contacts. The malware, disguised as applications like Telegram and KeePass, is delivered through seemingly benign installers.

Complex Malware Infrastructure

Group-IB’s findings indicate that HEAVYGRAM was first spotted in September 2023. Its Python-based architecture utilizes Telegram for command-and-control (C2) operations, enabling actions like data theft, microphone activation, and password exfiltration.

The malware’s operational structure is intricate, employing a prefix system to execute commands and manage data exfiltration. Its delivery methods include scripts, HTA files, and executables embedded with archives, often supported by the CRUDEEXCLUDE utility to stage malware.

Significance and Future Implications

These cyber activities underscore the ongoing threat posed by state-affiliated hackers. The extensive use of Telegram for C2 communications highlights the adaptability and resourcefulness of these actors, leveraging encrypted platforms for stealth operations.

As cybersecurity landscapes evolve, understanding and mitigating such threats is crucial for protecting sensitive data and maintaining digital security. Organizations must remain vigilant and adopt robust defense strategies to counteract these evolving cyber threats.

The Hacker News Tags:cyber espionage, Cybersecurity, data breaches, Group-IB, Handala Hack, HEAVYGRAM, Iran hackers, Malware, MOIS, Telegram

Post navigation

Previous Post: FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
Next Post: Orkes Conductor Flaw Exploited in Recent Cyber Attacks

Related Posts

Optimizing SOC with AI and Human Expertise Optimizing SOC with AI and Human Expertise The Hacker News
GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies The Hacker News
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory The Hacker News
Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks The Hacker News
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups The Hacker News
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service
  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service
  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark