Home » Robotics » A Telegram Backdoor Called HEAVYGRAM Is How Iran’s Handala Group Steals Your Credentials

A Telegram Backdoor Called HEAVYGRAM Is How Iran’s Handala Group Steals Your Credentials

A Telegram Backdoor Called HEAVYGRAM Is How Iran's Handala Group Steals Your Credentials

A hacking collective with ties to Iran has turned one of the world’s most popular messaging apps into a surveillance weapon. Researchers have linked the group known as Handala Hack to a previously undocumented backdoor called HEAVYGRAM, a malware strain that piggybacks on Telegram’s infrastructure to quietly siphon passwords, system data, and sensitive files from compromised machines. The discovery, Hacker News reporting details, marks a significant escalation in the group’s technical sophistication and underscores how state-aligned threat actors are increasingly co-opting legitimate platforms to hide malicious traffic in plain sight. This tactic mirrors patterns seen in other state-sponsored intrusions — something Future Wire has tracked in coverage of Google Gemini being manipulated through misconfigured enterprise systems.

a laptop screen displaying a Telegram desktop interface with an active chat window, photographed on a cluttered office desk at night with dim ambient lighting

Handala Hack first surfaced in late 2023, positioning itself as a pro-Palestinian hacktivist group while primarily targeting Israeli organizations. Security researchers have since assessed the group as operating with at least tacit support from Iranian state interests, given the precision and persistence of its campaigns. HEAVYGRAM represents a notable leap from the group’s earlier reliance on wiper malware and data-leak operations. Instead of destroying infrastructure, this tool is built to watch, record, and report back — a shift toward long-term espionage over short-term disruption.

How HEAVYGRAM Uses Telegram as a Command Channel

The backdoor’s core trick is elegant and difficult to block at the network level. Rather than connecting to a hard-coded command-and-control server — a setup that defenders can detect and sinkhole — HEAVYGRAM communicates through legitimate Telegram bot APIs. Traffic to Telegram’s servers is encrypted and indistinguishable from normal app usage, meaning firewalls and intrusion detection systems that whitelist the platform have no easy way to flag the exfiltration. The malware registers itself as a Telegram bot, receives instructions from an operator-controlled channel, and pushes stolen data back through the same pipe.

Once deployed on a victim machine, HEAVYGRAM is capable of harvesting stored browser passwords, capturing screenshots, enumerating running processes, and collecting system metadata. The credential-theft module specifically targets Chromium-based browsers, where login data is stored in a locally encrypted SQLite database — a well-known but highly effective attack surface. Researchers noted that the malware also checks for the presence of security tools and antivirus software before executing its full payload, a sign of deliberate operational security built into its design.

a close-up of a desktop computer monitor showing a terminal window with scrolling text output, situated in a dimly lit home office with cables visible in the background

The Broader Threat Picture and What Defenders Should Know

The HEAVYGRAM campaign is not an isolated incident. It is part of a wider pattern in which Iran-linked actors weaponize consumer apps and trusted platforms to lower the forensic footprint of their intrusions. Using Telegram means the group can operate without registering domains, purchasing bulletproof hosting, or managing server infrastructure — all activities that create detectable signatures. The approach also gives operators plausible deniability, since Telegram traffic alone is not evidence of compromise. This is exactly the kind of human-exploitable trust gap that energy grid security researchers have warned makes detection so difficult across critical infrastructure sectors.

For defenders, the practical guidance is straightforward even if implementation is not: organizations should enforce application allowlisting to restrict which processes can initiate outbound connections, audit Telegram bot API traffic at the proxy layer where possible, and treat unexpected credential database access as an immediate alerting trigger. The HEAVYGRAM discovery also reinforces the case for monitoring process behavior rather than relying on signature-based detection alone — the malware’s use of a legitimate platform means it will not match any known malicious domain or IP block. Given Handala’s primary focus on Israeli governmental, military-adjacent, and technology sector targets, organizations operating in that threat landscape should treat this campaign as active and ongoing rather than a theoretical risk.

Follow Future Wire

Subscribe to Future Wire!

Please choose one:

We don’t spam! Read our privacy policy for more info.

Subscribe to Future Wire!

Please choose one:

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *