Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

A sophisticated hacking campaign linked to Iranian actors has been uncovered, leveraging a previously unknown backdoor in the Telegram messaging app. Dubbed “HEAVYGRAM,” this exploit allows hackers to gain access to sensitive information, including passwords, from compromised devices. The operation, dubbed “Handala,” is believed to have targeted organizations and individuals with ties to countries critical of Iran’s government.

At the heart of the Handala campaign lies HEAVYGRAM, a custom-built backdoor that seamlessly integrates into Telegram’s architecture. By manipulating Telegram’s code, hackers can inject malware onto infected devices, allowing for remote control and data exfiltration. This level of access enables attackers to steal sensitive information, including login credentials, which can be used for further exploitation or sold on the dark web.

The scope of the Handala campaign is still being determined, but it appears to have targeted individuals with ties to countries that have clashed with Iran in recent years. The United States, Israel, and Saudi Arabia are among those believed to have been affected by this operation. It’s worth noting that Telegram’s encryption protocols were not compromised; rather, the vulnerability lies in the app’s internal code, making it a particularly insidious threat.

The implications of HEAVYGRAM extend far beyond mere identity theft. By granting hackers access to sensitive information and control over compromised devices, this backdoor creates an active attack path – a direct conduit for malicious actors to wreak havoc on targeted systems. Once inside, attackers can map the victim’s network, identifying key choke points that can be exploited to further breach security.

As the cybersecurity community grapples with the full extent of the Handala campaign, it becomes increasingly clear why HEAVYGRAM poses such a significant threat. This type of exploit not only allows for targeted attacks but also enables hackers to create sophisticated phishing campaigns and other social engineering tactics that can deceive even the most security-conscious individuals.

For organizations and individuals concerned about their vulnerability to this type of attack, it’s essential to prioritize vigilance in the face of potential threats. Conduct regular vulnerability assessments, maintain up-to-date software, and remain informed about emerging threats like HEAVYGRAM. By staying proactive and prepared, you can mitigate the risks associated with sophisticated hacking campaigns like Handala.


Source: The Hacker News — 2026-09-17