Cybersecurity experts have tied a sophisticated hacking campaign, code-named Handala, to a previously unknown backdoor in the popular Telegram messaging app called HEAVYGRAM. The discovery has significant implications for millions of users worldwide who rely on Telegram as their primary means of secure communication.
The Handala campaign is believed to be linked to Iranian threat actors, and it’s been quietly operating since at least 2024. According to researchers, the attackers exploited vulnerabilities in various third-party apps to gain access to sensitive data stored within those applications. The HEAVYGRAM backdoor, which was found embedded in some Telegram desktop clients, enabled the hackers to intercept encrypted chat sessions, steal passwords, and even spread malware to other devices.
The mechanism behind the Handala campaign is rooted in a technique known as cross-domain privilege escalation (CDPE). Essentially, this involves mapping the privileges of one domain or application to another, allowing attackers to escalate their access levels within a network. By exploiting these mapped privileges, hackers can create backdoors and intercept sensitive data without being detected.
One key aspect of the Handala campaign is its ability to remain undetected for extended periods. According to researchers, the attackers used a combination of sophisticated techniques, including code obfuscation and anti-debugging measures, to evade detection by security software. This stealth capability has allowed the hackers to stay one step ahead of their targets.
The implications of this discovery are far-reaching, as millions of Telegram users worldwide could be at risk of having their sensitive data compromised. The HEAVYGRAM backdoor is particularly concerning because it’s capable of intercepting encrypted chat sessions, essentially rendering the security of these conversations meaningless. Furthermore, the backdoor can also spread malware to other devices, creating a potential chain reaction of infections.
In light of this discovery, users are advised to exercise extreme caution when using Telegram or any other messaging app that relies on third-party plugins or integrations. By understanding how CDPE works and being aware of the risks associated with HEAVYGRAM, individuals can take steps to protect their sensitive data from falling into the wrong hands.
Source: The Hacker News — 2026-09-17