HackerFeeds

CyberSecurity News

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Hacker News
· September 17, 2026

AI summary

Iranian hackers associated with the Handala Hack persona have been linked to a Telegram-based backdoor called HEAVYGRAM. This backdoor allows for remote command execution and can steal sensitive information, including passwords. It also enables the discovery of system, network, and process information, as well as the exfiltration of data and Telegram session files. Additionally, HEAVYGRAM can capture screenshots and load DLLs. The hackers have also been tied to a Delphi-based utility known as CRUDEEXCLUDE.

Threat groups mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.