THREATOPS
THREAT OPSThreat News › HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

medgroupib_blog

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

Attributed threat actors

Original source: https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2/