Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer technical support or acts like a trusted contact, then convinces the victim to install a trojanized “legitimate” app.
How the attack worked
The campaign linked to the Handala Hack persona begins not with an email but with a direct message. Attackers reach out through Telegram, WhatsApp, or Instagram, presenting themselves as technical support or as a trusted contact. Once a rapport is established, the conversation shifts toward a request: install an update or installer to fix a supposed problem. The file handed over is not what it claims to be. It masquerades as a legitimate application such as Pictory, KeePass, or Telegram, but actually contains a second-stage implant called HEAVYGRAM.
HEAVYGRAM is notable for using Telegram itself as its command-and-control channel. Once active, it can steal saved passwords, capture screenshots, and copy data from Telegram and WhatsApp, giving the operator ongoing visibility into a victim's communications and credentials.
Why it succeeded
This approach works because it exploits trust built through familiar, everyday channels rather than a suspicious email attachment. A message from what appears to be a known contact or a helpful support agent lowers a target's guard. Researchers describe the operation as a multi-stage infection chain that combines tailored social engineering, application masquerading, and persistence, meaning the deception does not rely on a single trick but on layering several convincing elements together.
What to watch for
- Unsolicited offers of technical help arriving through chat apps rather than official support channels
- Pressure to download and run an installer or update sent directly in a message, instead of through an app store or vendor website
- App or installer names that match well-known tools like Telegram or KeePass, but whose source cannot be verified
- Contacts who suddenly ask you to install software, even if their profile or account looks familiar
How to build resistance
Organizations, especially those supporting journalists, NGO staff, and executives who rely heavily on messaging apps, should reinforce a simple rule: software and updates should only come from official vendor sites or app stores, never from a direct message. Staff should be encouraged to treat unsolicited tech support outreach as suspicious by default, even when it appears to come from someone they recognize. High-risk teams covering sensitive topics or operating in adversarial environments may benefit from additional, focused training on messaging-app lures and application masquerading, since these groups have been specifically named as targets of this type of campaign. Building a habit of pausing before installing anything sent through chat, and verifying requests through a separate channel, can blunt the effectiveness of this kind of layered social engineering.
This technique maps to MITM-relevant behaviors such as Phishing via Service and User Execution: Malicious File, both of which rely on convincing a person to take an action rather than exploiting a technical flaw.
Key findings
- Attackers use messaging apps (Telegram/WhatsApp/Instagram) to initiate contact and build trust before delivering malware.
- Pretexts include offering “technical support” or posing as “trusted contacts.”
- Malware is delivered as a trojanized installer masquerading as legitimate apps such as Pictory, KeePass, and Telegram.
- HEAVYGRAM uses Telegram for command-and-control and can steal saved passwords, capture screenshots, and copy Telegram/WhatsApp data.
- Researchers describe a “multi-stage infection chain” combining social engineering, app masquerading, and persistence.
Who’s being targeted
- Commonly targeted roles: Journalists/Editorial teams, NGO/advocacy staff, Executive leadership, Anyone using Telegram/WhatsApp/Instagram for work.
- Affected industries: Journalism/Media, Activist and civil society groups, Political opposition groups.
- Attack channels: telegram.
- Impersonated: Technical support / trusted contact (via messaging app).
Red flags to watch for
- Unsolicited “tech support” offered over chat apps
- Pressure to install an app/update sent via message instead of official app store/vendor site
- Installer/app name matches common tools (Telegram/KeePass) but source is unofficial
Frequently asked questions
How does the Handala Hack attack start?
It begins with social engineering on messaging apps like Telegram, WhatsApp, and Instagram, where the attacker poses as tech support or a trusted contact to build rapport with the target.
What malware is delivered in this campaign?
Victims are convinced to install a trojanized app disguised as legitimate software such as Pictory, KeePass, or Telegram, which contains a second-stage implant known as HEAVYGRAM.
What can HEAVYGRAM do once installed?
HEAVYGRAM uses Telegram for command-and-control and can steal saved passwords, capture screenshots, and copy Telegram and WhatsApp data.
Who is being targeted by this campaign?
Reported targets include journalists, NGO and activist staff, executive leadership, and other individuals who rely on Telegram, WhatsApp, or Instagram for work.
Read the video transcript
Imagine this Telegram DM: "Hi, I can help with your KeePass issue. Install this update so I can fix it." Looks helpful, right? Researchers tied this to Handala using a backdoor called HEAVYGRAM. They chat you up on Telegram, WhatsApp, or Instagram, then send a trojan installer pretending to be Pictory, KeePass, or even Telegram itself. Here’s the nasty part: once you run it, HEAVYGRAM quietly talks back over Telegram, can steal saved passwords, grab screenshots, and copy your Telegram and WhatsApp chats. If anyone DMs you tech support and sends an installer, don’t run it, go to the official app store or vendor site yourself and download only from there.