Handala Uses Fake “Support” Chats to Drop Malware

The Hacker News · High sophistication
Last updated September 18, 2026

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer technical support or acts like a trusted contact, then convinces the victim to install a trojanized “legitimate” app.

How the attack worked

The campaign linked to the Handala Hack persona begins not with an email but with a direct message. Attackers reach out through Telegram, WhatsApp, or Instagram, presenting themselves as technical support or as a trusted contact. Once a rapport is established, the conversation shifts toward a request: install an update or installer to fix a supposed problem. The file handed over is not what it claims to be. It masquerades as a legitimate application such as Pictory, KeePass, or Telegram, but actually contains a second-stage implant called HEAVYGRAM.

HEAVYGRAM is notable for using Telegram itself as its command-and-control channel. Once active, it can steal saved passwords, capture screenshots, and copy data from Telegram and WhatsApp, giving the operator ongoing visibility into a victim's communications and credentials.

Why it succeeded

This approach works because it exploits trust built through familiar, everyday channels rather than a suspicious email attachment. A message from what appears to be a known contact or a helpful support agent lowers a target's guard. Researchers describe the operation as a multi-stage infection chain that combines tailored social engineering, application masquerading, and persistence, meaning the deception does not rely on a single trick but on layering several convincing elements together.

What to watch for

  • Unsolicited offers of technical help arriving through chat apps rather than official support channels
  • Pressure to download and run an installer or update sent directly in a message, instead of through an app store or vendor website
  • App or installer names that match well-known tools like Telegram or KeePass, but whose source cannot be verified
  • Contacts who suddenly ask you to install software, even if their profile or account looks familiar

How to build resistance

Organizations, especially those supporting journalists, NGO staff, and executives who rely heavily on messaging apps, should reinforce a simple rule: software and updates should only come from official vendor sites or app stores, never from a direct message. Staff should be encouraged to treat unsolicited tech support outreach as suspicious by default, even when it appears to come from someone they recognize. High-risk teams covering sensitive topics or operating in adversarial environments may benefit from additional, focused training on messaging-app lures and application masquerading, since these groups have been specifically named as targets of this type of campaign. Building a habit of pausing before installing anything sent through chat, and verifying requests through a separate channel, can blunt the effectiveness of this kind of layered social engineering.

This technique maps to MITM-relevant behaviors such as Phishing via Service and User Execution: Malicious File, both of which rely on convincing a person to take an action rather than exploiting a technical flaw.

Key findings

  • Attackers use messaging apps (Telegram/WhatsApp/Instagram) to initiate contact and build trust before delivering malware.
  • Pretexts include offering “technical support” or posing as “trusted contacts.”
  • Malware is delivered as a trojanized installer masquerading as legitimate apps such as Pictory, KeePass, and Telegram.
  • HEAVYGRAM uses Telegram for command-and-control and can steal saved passwords, capture screenshots, and copy Telegram/WhatsApp data.
  • Researchers describe a “multi-stage infection chain” combining social engineering, app masquerading, and persistence.

Who’s being targeted

  • Commonly targeted roles: Journalists/Editorial teams, NGO/advocacy staff, Executive leadership, Anyone using Telegram/WhatsApp/Instagram for work.
  • Affected industries: Journalism/Media, Activist and civil society groups, Political opposition groups.
  • Attack channels: telegram.
  • Impersonated: Technical support / trusted contact (via messaging app).

Red flags to watch for

  • Unsolicited “tech support” offered over chat apps
  • Pressure to install an app/update sent via message instead of official app store/vendor site
  • Installer/app name matches common tools (Telegram/KeePass) but source is unofficial
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the Handala Hack attack start?

It begins with social engineering on messaging apps like Telegram, WhatsApp, and Instagram, where the attacker poses as tech support or a trusted contact to build rapport with the target.

What malware is delivered in this campaign?

Victims are convinced to install a trojanized app disguised as legitimate software such as Pictory, KeePass, or Telegram, which contains a second-stage implant known as HEAVYGRAM.

What can HEAVYGRAM do once installed?

HEAVYGRAM uses Telegram for command-and-control and can steal saved passwords, capture screenshots, and copy Telegram and WhatsApp data.

Who is being targeted by this campaign?

Reported targets include journalists, NGO and activist staff, executive leadership, and other individuals who rely on Telegram, WhatsApp, or Instagram for work.

Read the video transcript

Imagine this Telegram DM: "Hi, I can help with your KeePass issue. Install this update so I can fix it." Looks helpful, right? Researchers tied this to Handala using a backdoor called HEAVYGRAM. They chat you up on Telegram, WhatsApp, or Instagram, then send a trojan installer pretending to be Pictory, KeePass, or even Telegram itself. Here’s the nasty part: once you run it, HEAVYGRAM quietly talks back over Telegram, can steal saved passwords, grab screenshots, and copy your Telegram and WhatsApp chats. If anyone DMs you tech support and sends an installer, don’t run it, go to the official app store or vendor site yourself and download only from there.

Similar attacks

Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Iranian Spies Lure Targets via WhatsApp to Drop Malware

Iranian Spies Lure Targets via WhatsApp to Drop Malware

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI…

September 16, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran-Linked Spyware Posed as Apps on WhatsApp

Iran-Linked Spyware Posed as Apps on WhatsApp

UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware…

September 15, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026