APTHandala Hack Turns Telegram Into a Control Channel for Windows Espionage
HEAVYGRAM uses Telegram bots to control Windows systems, steal credentials, capture data, evade Defender, and deploy further malware.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
APTHEAVYGRAM uses Telegram bots to control Windows systems, steal credentials, capture data, evade Defender, and deploy further malware.
MalwarePhantomRaven malware hid in 100+ npm packages to steal developer credentials and CI/CD secrets.
MalwareFake GitHub repos impersonate LastPass and 39 apps to spread Rapuncel stealer and a signed driver that kills 145 security tools to steal credentials.
Malware13 malicious npm packages deploy WeaselBiscuit, a JS stealer that harvests Chrome extension LevelDB data, clipboard and keystrokes via in-memory loader.
RansomwareShinyHunters hacked Clop's Tor leak site via Grav CMS flaw, defaced it, claims server logs and onion keys, and threatens 72-hour extortion.
APTNorth Korea-linked WaterPlum used fake job interviews to infect 30,000 devices, steal $10.5M in crypto and gain access to corporate networks.
APTTransparent Tribe uses Rust backdoor RUSTYSHADE and file stealers via private GitHub repos to spy on Indian and Afghan government targets.
MalwareRatHat Android malware abuses Accessibility to enable wireless ADB, persist via reverse proxy, and use AI for screen navigation and banking theft.
RansomwareManufacturing ransomware rose 40% in 2026 with 1,183 victims. JLR's £1.9B loss shows impact as new groups target Europe's supply chain.
APTChina-linked FamousSparrow deployed SparroWocky backdoor against Latin American governments for espionage, using DLL sideloading and stealth techniques.
APTUS, UK and Dutch agencies expose CHOSEN BRICK, Iranian Windows malware spreading via WhatsApp and Telegram to spy on dissidents, journalists and activists.
APTKaspersky reports NightEagle, Hacking Cat and Toy Ghouls targeting Russian firms with Exchange exploits, backdoors, ransomware and wipers.