Threat Advisory

Handala Hack Uses HEAVYGRAM Windows Backdoor for Surveillance

Threat: Malware
Threat Actor Name: Handala Hack
Threat Actor Type: Nation-Sponsored or State-Sponsored
Targeted Region: Iran, UK, Israel, United States
Threat Actor Region: Iran
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

HEAVYGRAM is a multi-functional Windows backdoor/persistent implant attributed to Handala Hack with moderate confidence. It leverages the Telegram bot API for exfiltration and command-and-control, allowing operators to execute commands remotely, exfiltrate data and screenshots, establish persistence and run additional payloads. HEAVYGRAM's infection chain involves tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest.

It operates via a multi-stage infection process, with initial delivery via WSF/VBS scripts, VBS scripts and HTML applications (HTA), executables with embedded archives, or CRUDEEXCLUDE executables with embedded archives. The persistent implant relies on several additional files, including an internal config.py file containing hardcoded configuration strings, and rantom.txt – an encrypted text file with custom function definitions.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

HEAVYGRAM is a multi-functional Windows backdoor/persistent implant attributed to Handala Hack with moderate confidence. It leverages the Telegram bot API for exfiltration and command-and-control, allowing operators to execute commands remotely, exfiltrate data and screenshots, establish persistence and run additional payloads. HEAVYGRAM's infection chain involves tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest.

It operates via a multi-stage infection process, with initial delivery via WSF/VBS scripts, VBS scripts and HTML applications (HTA), executables with embedded archives, or CRUDEEXCLUDE executables with embedded archives. The persistent implant relies on several additional files, including an internal config.py file containing hardcoded configuration strings, and rantom.txt – an encrypted text file with custom function definitions.[emaillocker id="1283"]

It handles C2 communication via two functions: send_initial_message and send_health_msg. The malware has been used in operations targeting journalists, dissidents, and other individuals of interest to Iran, further illustrating how tooling associated with the actor can support targeted collection while feeding broader intrusions and hack-and-leak operations.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.006 Command and Scripting Interpreter Python
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Exfiltration E1020 Automated Exfiltration
Persistence F0012 Registry Run Keys / Startup Folder
Execution E1204 User Execution

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu