A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation.
The campaign combines targeted social engineering, Microsoft Defender exclusion abuse, multi-stage loaders, and Telegram-based command-and-control to surveil Iranian dissidents, journalists, and people perceived as opponents of the Iranian government.
The research expands on U.S. government disclosures issued earlier this year. On March 19, the U.S.
Department of Justice seized four domains it said were used by Iran’s Ministry of Intelligence and Security (MOIS) to support cyber-enabled psychological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to.
The DOJ affidavit described “Heavygram” in incidents involving victims contacted through Telegram and tricked into executing malware disguised as legitimate software.
The FBI subsequently published an expanded HEAVYGRAM FLASH report on September 15, detailing a Windows-focused surveillance toolkit that uses Telegram bots, groups, and user accounts as command-and-control infrastructure.
UK and Dutch authorities track the activity under the name CHOSEN BRICK, while the FBI attributes HEAVYGRAM operations to actors working for MOIS.
These Delphi-based samples display convincing graphical interfaces while silently unpacking embedded archives and launching HEAVYGRAM’s persistent implant.
A core feature is defense evasion. CRUDEEXCLUDE uses PowerShell to add attacker-controlled locations to Microsoft Defender exclusions, preventing files written to those paths from being scanned.
Observed exclusions include directories resembling legitimate Windows or application locations, such as %ALLUSERSPROFILE%MicrosoftDistributionsysmain, C:Users, and %ALLUSERSPROFILE%SMQDServicePackages488ht1-8ww648q.
The malware decodes an embedded payload, saves it as a ZIP archive, extracts it into C:ProgramData, and launches the HEAVYGRAM binary with CreateProcessW.
This approach gives the operators a reliable route to install their surveillance implant after weakening local endpoint protections.
The use of fake applications is particularly effective against high-risk targets who may expect to receive messaging, password-management, or media-related software.

Earlier delivery lures impersonated KeePass, Telegram, WhatsApp, and Pictory installers, while a Persian-language screensaver lure referenced a “supplementary and expelled list,” indicating targeting tailored to academics or students.
HEAVYGRAM’s second-stage implant is a PyInstaller-packaged Python executable built for persistence and remote access on Windows.
Group-IB identified CRUDEEXCLUDE, executables masquerading as trusted programs such as Pictory and Telegram.
It creates a mutex to avoid duplicate execution, writes configuration data under %APPDATA%Configconfig.xml, collects the compromised host’s name, and uses hardcoded Telegram bot credentials and group or user identifiers to communicate with operators.
HEAVYGRAM Malware Deployment
The implant sends an initial beacon and periodic health checks over Telegram, allowing operators to identify active machines without maintaining conventional malicious infrastructure.
It can receive textual commands and file attachments through Telegram’s bot API, making detection more difficult because the traffic blends with a widely used legitimate cloud messaging service.
Commands include arbitrary shell execution through os.popen, process enumeration, public IP discovery, system-information collection, screenshot capture, payload deployment, registry-based persistence, and theft of Telegram Desktop data.
HEAVYGRAM can also download and execute additional executables, unpack ZIP-delivered payloads, and use DLL side-loading by copying the legitimate bthudtask.exe binary into the spoofed C:Windows SysWOW64 directory, which contains an intentional trailing space.
Public reporting on the FBI advisory further indicates that variants can collect browser-stored communications and credentials, record audio, delete files, and retrieve additional malware.
Indicators include suspicious Run key persistence entries such as SMQDService or winappx, unexpected Telegram API connections, and the anomalous C:Windows SysWOW64 path.
Group-IB assesses that Handala Hack is not an independent hacktivist group, but an online persona associated with Void Manticore, also tracked as Storm-0842, Banished Kitten, and Red Sandstorm.
The operation has portrayed itself as a cyber-resistance movement, yet its target selection, infrastructure, destructive activity, leaks, intimidation, and alignment with Iranian state interests are consistent with a MOIS-linked coercive campaign.
The latest disclosures reinforce that the operation’s purpose extends beyond espionage.
A number of Delphi-based executables have also been identified which masquerade as legitimate applications such as Pictory and Telegram.
Access to victim systems and messaging accounts can support surveillance, public exposure, hack-and-leak operations, intimidation, and the identification of opposition figures.

The DOJ said the seized MOIS-linked sites had been used to claim responsibility for intrusions, publish stolen data, and call for violence against journalists, dissidents, and Israeli individuals.
Defenders should investigate PowerShell activity that modifies Defender exclusions, particularly when exclusions point to unusual ProgramData, download, or misspelled service directories.
They should also hunt for registry persistence involving SMQDService and winappx, examine executions of fake KeePass, Telegram, or Pictory installers, and monitor unusual outbound requests to api.telegram.org originating from endpoints that do not normally automate Telegram activity.
Organizations supporting journalists, activists, researchers, and diaspora communities should prioritize application allowlisting, Microsoft Defender tamper protection, phishing-resistant MFA, endpoint telemetry, and strict verification of software received through messaging platforms.
The campaign begins with trust-based contact and a convincing decoy; preventing the initial execution remains the most effective defense.
IOCs
| Type | SHA256 | SHA1 | MD5 |
| First stage | 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd | 0190940243f6535f51d43edafac943d493159e14 | b3c1a3eebefafe1346c6a864b5423182 |
| RAR artefact | 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 | 88a8d118ee190ac36cf684c2992f6ddd2dda517b | b2f6f40570ac9085b5463fdb623560de |
| Implant/Backdoor | d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e | 9108466c98df01033371483a789a0c23372c52f2 | 16602375fc2dae1eb54580ab7eda6567 |
| Encrypted text artefact | 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 | 53d41445e176bf53c5acd2dad533eda612b05855 | 7d3cce1f9dbaed585b61e6e903d69b9b |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

