Iran-Linked Hackers Use Telegram Backdoor to Steal Passwords

A sophisticated surveillance tool is turning a popular messaging app into a channel for spying, allowing attackers to bypass security controls and extract sensitive data from user devices.
Security researchers have linked a group known as Handala Hack to a surveillance backdoor that operates through Telegram. The tool, identified as HEAVYGRAM, allows attackers to control infected computers remotely, including the ability to take screenshots, capture microphone audio, and steal saved passwords from web browsers.
The threat actor is assessed to be affiliated with Iran’s Ministry of Intelligence and Security. According to The Hacker News, the group has targeted dissidents, journalists, and opposition figures. The malware uses the messaging platform not just for communication, but as a command-and-control channel to issue instructions and exfiltrate data.
Malware disguises itself as legitimate software
The infection process typically begins with social engineering. Attackers pose as trusted contacts or technical support on platforms like Instagram or WhatsApp. They then send files disguised as common applications, such as password managers or video tools, which actually contain the malicious code.
A companion tool called CRUDEEXCLUDE prepares the system for the main payload. It is designed to look like a standard Windows application with a graphical interface. Once active, it modifies security settings to prevent Microsoft Defender from scanning specific directories, effectively creating a blind spot for the subsequent malware installation.
Telegram serves as the remote control
The core of the operation relies on a Python-based script that interprets messages sent from a specific Telegram bot. Special prefixes in the message body trigger different actions. For example, one set of characters initiates the execution of system commands, while another enables a suite of spying functions.
These functions include listing running programs, retrieving the victim’s public IP address, and copying data from Telegram and WhatsApp applications. The malware can also download additional payloads and delete files to cover its tracks, all driven by simple text commands sent over the chat interface.
Targeting journalists and opposition figures
The U.S. Federal Bureau of Investigation has issued alerts regarding Iranian cyber actors targeting individuals opposed to the government. The goal is often intelligence collection and reputational harm. Canadian authorities have also reported on this activity, noting that journalists have been doxxed as part of these operations.
The trade-off for users who trust messages from unknown contacts is significant. While messaging apps are convenient, they can be leveraged to deliver complex spyware. The catch is that the malware persists in the system registry, meaning it returns automatically after a reboot unless specifically removed by advanced security tools.






