B
今週中
イランに関連するハクティビスト集団「Handala Hack」が、Telegramベースの監視バックドア「HEAVYGRAM」とDelphi製ユーティリティ「C…
📌 一言でいうと
イランに関連するハクティビスト集団「Handala Hack」が、Telegramベースの監視バックドア「HEAVYGRAM」とDelphi製ユーティリティ「CRUDEEXCLUDE」を使用していることが判明しました。CRUDEEXCLUDEはMicrosoft Defenderの除外パスを設定して検知を回避し、その後HEAVYGRAMを導入してパスワード窃取やリモートコマンド実行を行います。この活動は米国FBIによっても警告されており、機密情報の窃取を目的としたサイバー諜報活動の一環と考えられています。
🔍該当判定
- 業務でWindows PCを利用し、かつチャットツールに『Telegram』をインストールしている
- 身に覚えのないアプリや、出所不明のGUI(操作画面)付きソフトをWindowsにインストールした
- Windows Defenderの『除外設定(スキャン対象外)』に、心当たりのないフォルダやファイルが登録されている
- PCのレジストリ(自動起動設定)に、見覚えのないプログラムが追加されている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
不審なアプリケーションの実行を避け、Microsoft Defenderなどのエンドポイントセキュリティ製品の除外設定に意図しない変更がないか監視してください。また、Telegramなどのメッセージングアプリのセッションファイルが不当にアクセスされていないか確認することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】イラン系アクターによるHEAVYGRAM/CRUDEEXCLUDEの活動について
お疲れさまです。イランに関連する脅威アクター「Handala Hack」による新しいマルウェア活動に関する情報共有です。
■ 概要
攻撃者はまず「CRUDEEXCLUDE」というDelphi製ツールを用いてMicrosoft Defenderの除外パスを設定し、検知を回避します。その後、Telegramベースのバックドア「HEAVYGRAM」を導入し、リモートコマンド実行、パスワードおよびTelegramセッションファイルの窃取、スクリーンショット撮影などを行います。
■ 影響範囲
- Windows OS(Microsoft Defenderを利用している環境)
■ 対応手順
1. エンドポイントにおけるMicrosoft Defenderの「除外設定」に、管理者が意図しないパスが追加されていないか監査してください。
2. 不審なDelphi製バイナリや、Telegram APIと通信する未知のプロセスの有無を確認してください。
3. 組織内の特権アカウントにおけるセッション管理を強化してください。
■ 参考情報
- Group-IB Report / FBI Alert
対応優先度: 中
対応期限: 随時
お疲れさまです。イランに関連する脅威アクター「Handala Hack」による新しいマルウェア活動に関する情報共有です。
■ 概要
攻撃者はまず「CRUDEEXCLUDE」というDelphi製ツールを用いてMicrosoft Defenderの除外パスを設定し、検知を回避します。その後、Telegramベースのバックドア「HEAVYGRAM」を導入し、リモートコマンド実行、パスワードおよびTelegramセッションファイルの窃取、スクリーンショット撮影などを行います。
■ 影響範囲
- Windows OS(Microsoft Defenderを利用している環境)
■ 対応手順
1. エンドポイントにおけるMicrosoft Defenderの「除外設定」に、管理者が意図しないパスが追加されていないか監査してください。
2. 不審なDelphi製バイナリや、Telegram APIと通信する未知のプロセスの有無を確認してください。
3. 組織内の特権アカウントにおけるセッション管理を強化してください。
■ 参考情報
- Group-IB Report / FBI Alert
対応優先度: 中
対応期限: 随時
Subject: [Intel] Iranian Actor Activity: HEAVYGRAM and CRUDEEXCLUDE
Dear Team,
We are sharing intelligence regarding the Iran-linked threat actor 'Handala Hack' and their use of specialized malware.
■ Overview
The actor utilizes a Delphi-based utility called 'CRUDEEXCLUDE' to configure Microsoft Defender exclusion paths for defense evasion. Once the environment is prepared, they deploy 'HEAVYGRAM,' a Telegram-based surveillance backdoor capable of remote command execution, data exfiltration (including Telegram session files), and screenshot capture.
■ Scope
- Windows environments utilizing Microsoft Defender.
■ Recommended Actions
1. Audit Microsoft Defender exclusion lists for any unauthorized or suspicious paths.
2. Monitor for unknown Delphi-based binaries or unauthorized processes communicating with Telegram API endpoints.
3. Review session management and MFA for privileged accounts to mitigate the risk of session theft.
■ Reference
- Group-IB / FBI Alerts
Priority: Medium
Deadline: Ongoing
Dear Team,
We are sharing intelligence regarding the Iran-linked threat actor 'Handala Hack' and their use of specialized malware.
■ Overview
The actor utilizes a Delphi-based utility called 'CRUDEEXCLUDE' to configure Microsoft Defender exclusion paths for defense evasion. Once the environment is prepared, they deploy 'HEAVYGRAM,' a Telegram-based surveillance backdoor capable of remote command execution, data exfiltration (including Telegram session files), and screenshot capture.
■ Scope
- Windows environments utilizing Microsoft Defender.
■ Recommended Actions
1. Audit Microsoft Defender exclusion lists for any unauthorized or suspicious paths.
2. Monitor for unknown Delphi-based binaries or unauthorized processes communicating with Telegram API endpoints.
3. Review session management and MFA for privileged accounts to mitigate the risk of session theft.
■ Reference
- Group-IB / FBI Alerts
Priority: Medium
Deadline: Ongoing