Learn
active
Iran-Linked Handala Hack Group Deploys HEAVYGRAM Telegram Backdoor
- Engineer — Learn: HEAVYGRAM’s DLL sideloading and Telegram session file exfiltration techniques are worth factoring into threat models for environments where Telegram is used and where DLL loading paths are not locked down, but no patch or configuration action is indicated with zero exploitation signals.
- SOC/IR — Learn: The TTP set — remote command execution, screenshot capture, DLL sideloading, and Telegram session theft — maps roughly to ATT&CK T1574/T1113/T1552, but no IOCs are published here and targeting appears geopolitically scoped, so no immediate hunt is warranted; worth cataloguing for future detection logic around Telegram credential theft.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.