CyberSecurity News
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
AI summary
Iranian hackers associated with the Handala Hack persona have been linked to a Telegram-based backdoor called HEAVYGRAM. This backdoor allows for remote command execution and can steal sensitive information, including passwords. It also enables the discovery of system, network, and process information, as well as the exfiltration of data and Telegram session files. Additionally, HEAVYGRAM can capture screenshots and load DLLs. The hackers have also been tied to a Delphi-based utility known as CRUDEEXCLUDE.
Threat groups mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

