← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 17, 2026 · 07:20via Group-IB

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

Brief

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

Read more on Group-IB→