Cybersecurity researchers have linked a sophisticated new backdoor targeting Telegram to the Iran-aligned "hacktivist" group Handala Hack. The malware, dubbed HEAVYGRAM, marks a strategic pivot from the group's known destructive tactics toward stealthy surveillance and data theft.

Detailed in a recent report, HEAVYGRAM operates as a full-featured espionage tool designed to embed itself within the trusted Telegram ecosystem. It exploits user confidence in the platform to establish a foothold on compromised devices, offering attackers a broad set of malicious capabilities.

Once active, HEAVYGRAM enables remote command execution on the victim's system. It performs detailed reconnaissance, gathering system, network, and process information. Crucially, the malware can capture screenshots and exfiltrate data, with a specific focus on stealing Telegram session files—a tactic that allows attackers to hijack an active session without needing the user's password.

The campaign also employs a companion utility named CRUDEEXCLUDE, developed in Delphi, though its exact function remains under investigation.

This technique underscores a growing trend: threat actors are increasingly leveraging the trust in legitimate communication platforms to evade traditional security defenses. By operating within or alongside popular tools like Telegram, they bypass awareness focused on conventional phishing or malicious attachments.

The initial infection vector for HEAVYGRAM has not been publicly disclosed, leaving the delivery method unclear. The attribution to Handala Hack, previously linked to destructive operations, indicates a notable evolution in their tactics.

For users in Hong Kong, where Telegram is widely adopted for secure personal and business communications, this discovery highlights ongoing risks. It serves as a reminder that vigilance is essential, even on platforms considered secure.


網絡安全研究人員發現,一個針對Telegram的複雜新型後門程式與伊朗支持的「黑客行動主義」組織Handala Hack有關。這個名為HEAVYGRAM的惡意軟件標誌著該組織從已知的破壞性策略,轉向隱蔽監控和數據竊取的戰略轉變。

根據近期報告詳細描述,HEAVYGRAM作為一個全功能間諜工具運作,設計用於嵌入可信的Telegram生態系統。它利用用戶對平台的信任,在受感染設備上建立據點,為攻擊者提供廣泛的惡意功能。

一旦啟動,HEAVYGRAM可在受害者系統上執行遠程命令。它進行詳細的偵察,收集系統、網絡和進程信息。關鍵是,該惡意軟件能截取屏幕截圖並外洩數據,特別專注於竊取Telegram會話文件——這種策略使攻擊者無需用戶密碼即可劫持活躍會話。

此活動還使用了一個名為CRUDEEXCLUDE的配套工具,以Delphi開發,但其確切功能仍在調查中。

此技術凸顯了一個日益增長的趨勢:威脅行為者越來越多地利用對合法通信平台的信任來規避傳統安全防禦。通過在Telegram等流行工具內部或旁邊運作,他們繞過了針對傳統釣魚或惡意附件的意識。

HEAVYGRAM的初始感染媒介尚未公開披露,傳遞方式仍不明確。將其歸因於先前與破壞性行動有關的Handala Hack,表明其策略發生了顯著演變。

對於廣泛使用Telegram進行安全個人及商業通信的香港用戶而言,此發現突顯了持續存在的風險。它提醒即使在被認為安全的平台上,保持警惕仍然至關重要。

新聞來源 / Original News Source