Published: · Region: Middle East · Category: cyber

Iran‑Linked ‘Handala’ Hack Uses Telegram‑Controlled Backdoor to Steal Passwords and Messages

A campaign dubbed ‘Handala’ and linked to Iran is tied to malware that uses Telegram as a control channel for a backdoor able to steal passwords and messaging data, execute commands, capture screenshots, and download more malware, according to new technical research.

A hacking operation linked to Iran is turning a common messaging app into a command center for espionage.

Researchers have tied an Iran‑linked “Handala” campaign to a backdoor that is controlled over Telegram. Once installed, the malware can steal passwords and messaging data, run commands on the victim’s machine, capture screenshots, and pull down additional malicious tools. Telegram functions as the control channel that tells the backdoor what to do and where to send stolen information.

Using a mainstream app in this way helps the operators blend into normal network traffic. Many organizations allow Telegram, or at least don’t treat it as suspicious by default. That makes it harder for defenders to spot the difference between routine messaging and an active intrusion.

For targets in government, defense, or other sensitive sectors, the consequences are straightforward. Password theft can open access to email and internal systems; captured messages and screenshots can expose contacts, plans and internal documents; and the ability to fetch more malware turns one compromised device into a foothold for a wider breach.

The campaign illustrates how state‑linked groups increasingly rely on consumer platforms to hide their activity, narrowing the gap between everyday digital life and national security.

Key signals to watch are whether major organizations start tightening controls on Telegram in sensitive environments, whether Telegram itself moves against infrastructure linked to the backdoor, and whether future reporting connects Handala’s tools to specific intrusions against high‑value political or military targets.

Sources