HomeCyber BalkansHandala Hack Utilizes CRUDEEXCLUDE to Disable Defender Protections and Launch HEAVYGRAM

Handala Hack Utilizes CRUDEEXCLUDE to Disable Defender Protections and Launch HEAVYGRAM

Published on

spot_img

Emerging Malware Tactics Linked to Handala Hack Campaign: A New Threat Landscape

In the ever-evolving realm of cyber threats, a recent analysis has uncovered new malware samples named HEAVYGRAM and CRUDEEXCLUDE, which are suspected to be affiliated with the Iran-aligned Handala Hack operation. Researchers have established this connection with moderate confidence, revealing the meticulous tactics employed by the perpetrators in their targeted campaigns.

These insights stem from extensive research into a sophisticated campaign that uniquely combines social engineering, abuse of Microsoft Defender exclusions, multi-stage loaders, and Telegram-based command-and-control (C2) mechanisms. This multifaceted strategy is primarily aimed at surveilling Iranian dissidents, journalists, and individuals perceived as adversaries to the Iranian regime.

The ongoing research builds upon prior disclosures made by the U.S. government earlier this year. Notably, on March 19, the U.S. Department of Justice (DOJ) took significant action by seizing four domains allegedly utilized by the Iranian Ministry of Intelligence and Security (MOIS). These domains were said to support not only cyber-enabled psychological operations but also broader transnational repression. The seized domains include Handala-Hack[.]to and Handala-Redwanted[.]to.

The DOJ affidavit furnished compelling evidence detailing the modus operandi of Heavygram. Victims have been reported to be contacted via Telegram and subsequently deceived into executing malware disguised as legitimate software. This deceptive practice underlines the sophisticated psychological manipulation employed during the cyber operation.

Further highlighting the gravity of the situation, the FBI disseminated an expanded HEAVYGRAM FLASH report on September 15, which detailed a Windows-centric surveillance toolkit that capitalizes on Telegram bots, groups, and user accounts as its infrastructure for command and control. While UK and Dutch authorities classify the operation under the name CHOSEN BRICK, the FBI attributes the HEAVYGRAM efforts directly to individuals linked with the MOIS.

The malware samples identified reveal a significant level of sophistication. Specifically, the Delphi-based samples boast convincing graphical user interfaces, allowing them to silently unpack embedded archives and initiate the HEAVYGRAM’s persistent implant. A hallmark of its design is evasion of detection by security measures. CRUDEEXCLUDE employs PowerShell to append attacker-controlled paths to Microsoft Defender exclusions, effectively circumventing file scans. Observed exclusions resemble legitimate Windows installations, including directories like %ALLUSERSPROFILE%\MicrosoftDistribution\sysmain and C:\Users\\Downloads\Telegram Desktop.

The malware meticulously decodes an embedded payload, subsequently saving it as a ZIP archive. It extracts this archive into C:\ProgramData, launching the HEAVYGRAM binary through CreateProcessW. This sequence of actions effectively undermines local endpoint defenses and provides a reliable avenue for the operators to implant their surveillance tools.

The tactics employed are particularly effective against high-reward targets who may anticipate receiving various types of messaging, password-management, or media software. The initial lure utilized in earlier attacks involved impersonating well-known applications such as KeePass, Telegram, and WhatsApp. A notable Persian-language screensaver lure also indicated a targeted approach aimed at academics or students by referencing a "supplementary and expelled list."

The second stage of the HEAVYGRAM implant is notably a PyInstaller-packaged Python executable, designed to ensure both persistence and remote access on Windows systems. Researchers at Group-IB have identified CRUDEEXCLUDE executables masquerading as trusted programs. In addition to creating a mutex to avoid duplicate execution, the implant records configuration data under %APPDATA%\Config\config.xml and employs hardcoded Telegram credentials to maintain communication with operators.

The deployment of the HEAVYGRAM malware facilitates an array of malicious activities. It sends periodic beacons and health checks via Telegram, enabling operators to monitor active machines without engaging in the complexities of maintaining traditional malicious infrastructure. Commands sent to the implant allow for shell execution, process enumeration, system information collection, screenshot capture, and even data theft from Telegram Desktop.

Notably, evidence suggests that HEAVYGRAM could download additional executables, execute payloads from ZIP files, and employ DLL side-loading techniques. Public reporting on the FBI advisory has further revealed that different variants of the malware can compromise browser-stored communications, record audio, and retrieve additional malicious software.

As cybersecurity experts analyze the threat landscape, they observe various indicators associated with the HEAVYGRAM campaign. These include suspicious persistence entries, unconventional connections to the Telegram API, and peculiar directory paths that don’t align with typical operational procedures.

Group-IB posits that the Handala Hack operation should not be viewed as an independent hacktivist group but rather as a pseudonymous manifestation of a state-sponsored entity, connecting it back to broader Iranian interests. The operation’s facade of a cyber-resistance movement is contradicted by its strategies, target selection, and alignment with MOIS objectives, indicating a campaign designed not only for surveillance but for comprehensive coercive actions.

In light of these revelations, cybersecurity defenders are advised to scrutinize PowerShell behaviors modifying Defender exclusions while also employing proactive measures such as application allowlisting and the implementation of phishing-resistant multi-factor authentication. The overarching challenge lies in preventing the initial execution of malicious payloads, and organizations supporting vulnerable communities must prioritize robust cybersecurity protocols to mitigate these advanced threats.

As the threat landscape continues to evolve, the core message remains: staying ahead of such sophisticated campaigns requires diligence, technological adaptability, and a commitment to safeguarding vulnerable populations against targeted cyber operations.

Source link

Latest articles

New RatHat Android Malware Uses AI to Steal Financial Data

Emerging Android Malware ‘RatHat’ Targets Sensitive User Data In an alarming development within the realm...

China Advocates for Enhanced AI Oversight

Spain Reports First AI Agent-Linked Data Breach; NightmareStresser Domains Seized On September 17, 2026, the...

Security Spending is Increasing, But Not for the Average CISO

In the ever-evolving landscape of cybersecurity, the allocation of security budgets appears to be...

Cisco addresses critical ISE vulnerability, marking the second zero-day patch of the week

Cisco Issues Urgent Patches for Critical Authentication Bypass Vulnerability In a significant development, Cisco has...

More like this

New RatHat Android Malware Uses AI to Steal Financial Data

Emerging Android Malware ‘RatHat’ Targets Sensitive User Data In an alarming development within the realm...

China Advocates for Enhanced AI Oversight

Spain Reports First AI Agent-Linked Data Breach; NightmareStresser Domains Seized On September 17, 2026, the...

Security Spending is Increasing, But Not for the Average CISO

In the ever-evolving landscape of cybersecurity, the allocation of security budgets appears to be...