A familiar messaging platform can become much more than a communication tool when threat actors turn it into part of their attack infrastructure.
Group-IB
#ThreatIntelligence uncovered 29 new samples associated with the
#HEAVYGRAM and
#CRUDEEXCLUDE malware families, providing new insight into activity attributed with moderate confidence to
#HandalaHack.
Key Highlights:
🔹 HEAVYGRAM is a Windows backdoor capable of remote command execution, screenshot capture, system and process discovery, Telegram session data exfiltration and persistence through Windows autorun registry keys.
🔹 Telegram-based C2 is central to the operation. HEAVYGRAM uses Telegram bots, users and groups to receive commands, exchange files and exfiltrate data.
🔹 Application masquerading is used to deceive victims, with samples posing as legitimate applications including Telegram, KeePass and Pictory.
🔹 CRUDEEXCLUDE supports defense evasion by adding paths to Microsoft Defender exclusions before deploying additional stages.
🔹 Multiple delivery mechanisms were identified, including WSF, VBS, HTA and executables containing embedded archives.
🔹 Much of the identified
#Telegram infrastructure continues to remain present on Telegram as of 2026, rather than deleted, although some of the identified accounts have since been taken over by unrelated actors and repurposed for other activity.
Read the full technical analysis to understand the infection chain, malware capabilities, infrastructure and defensive recommendations:
link.group-ib.com/4hwWtHq