Iran's Telegram Spy Tool, a DNS Time Bomb, and the Data Broker That Faked Its Own CEO
Thursday, September 17, 2026 · 5-minute read
Iran-linked hackers operating under the name "Handala Hack" have been caught using a sneaky program called HEAVYGRAM that hides inside Telegram. Once installed, it can steal your passwords, take screenshots, and hand full control of your computer to someone overseas. The FBI first warned about this group back in March 2026, and researchers at Group-IB have now connected the dots between the malware and the Iranian-linked persona.
↗ The Hacker NewsA Chinese state-sponsored hacking group called FamousSparrow — previously linked to attacks on hotels and governments worldwide — is now targeting government organizations across Latin America. They're using a brand-new backdoor named SparroWocky, which researchers at ESET say is unusually sophisticated and built to avoid detection. Oddly, early versions of the malware included the opening lines of Lewis Carroll's nonsense poem "Jabberwocky" embedded inside the code.
↗ The Hacker News / BleepingComputerGovernment agencies are sounding fresh alarms about another Iranian hacking campaign, this one using spyware called CHOSEN BRICK. The malware runs on Windows and is being used to spy on dissidents, activists, and journalists — people who criticize the Iranian government. If you or someone you know fits that profile, extra caution online is warranted right now.
↗ BleepingComputerAttackers took over the official HBO Max account on Reddit and used it to post fake ads loaded with a ClickFix scam. ClickFix is a technique where victims are shown a fake error message and told to manually run a command to "fix" it — but that command actually installs malware. Because the ads came from a verified, trusted brand account, many users had no reason to be suspicious.
A banking malware operation active since mid-2025 is using a toolkit called KREMLIN to quietly install malicious extensions in Chrome and Edge — bypassing the normal checks that are supposed to prevent this. Once installed, these browser extensions steal your login credentials, session cookies, and other sensitive data. Your bank login, saved passwords, and active sessions are all at risk.
Every version of Unbound before 1.26.1 has a serious flaw in the part that validates DNS security signatures. An attacker who controls a malicious DNS zone can send a specially crafted response that crashes the resolver and runs their own code on your server — from anywhere on the internet, with no login required. This is about as bad as it gets for a network-facing service.
Status: Patch available — update to Unbound 1.26.1 immediately. No active exploitation confirmed yet.
A second serious bug was found in Unbound at the same time, this one in how the software processes CNAME records. It can corrupt memory in a way that could also lead to remote code execution on vulnerable systems, depending on how the software was compiled. It was discovered by a researcher at Anthropic — the AI company — and reported responsibly.
Status: Fixed in Unbound 1.26.1. No known active exploitation.
Cisco has issued emergency patches for a maximum-severity zero-day vulnerability in its Identity Services Engine — software that many large organizations use to control who can access their network. Attackers are already actively exploiting this flaw in the wild. If your organization uses Cisco ISE, this needs to move to the top of your IT team's to-do list today.
Status: Patch available from Cisco. Actively exploited — patch immediately.
The FBI has seized the domains belonging to NightmareStresser, a platform that let anyone — with no hacking skills — pay a small fee to knock websites and online services offline with a flood of fake traffic. These services are called booter or stresser services, and NightmareStresser was one of the oldest and most widely used. The takedown removes a tool that was routinely used for harassment, extortion, and disrupting businesses. It's part of an ongoing push by US law enforcement to dismantle the commercial infrastructure that makes cybercrime easy and accessible.
If you've ever Googled your own name and found a website displaying your home address, phone number, and family members' details, you've probably encountered a data broker. Radaris.com was one of the biggest and most brazen of the bunch — and it just lost control of its own domain name in court after years of spectacular legal dodge-ball.
The story starts in New Jersey, where a law called Daniels Law gives police officers, judges, and other government officials the right to have their personal information scrubbed from data broker sites. A company called Atlas Data Privacy Corp sued Radaris for ignoring removal requests. What followed was a masterclass in stalling: Radaris kept shifting ownership of its domains through shell companies in places like the Marshall Islands, the British Virgin Islands, and the Seychelles. Every time a court judgment got close, a new mystery company would appear on paper as the "real" owner. At one point, investigators discovered that a freshly created Marshall Islands entity Radaris claimed was running the site didn't even exist yet when the paperwork was filed.
The co-founders — Russian-born brothers Igor and Dmitry Lubarsky, living in Massachusetts — even invented a fake CEO named "Gary Norden" to put on press releases while they sought investment. Their own attorney later admitted the name was made up. Despite all this, the legal games worked for nearly a decade. Previous plaintiffs gave up, exhausted by the procedural runaround. This time, Atlas committed to seeing it through. On August 26, 2026, after the defendants once again failed to appear and defend themselves, a judge ordered the radaris.com domain and more than a dozen related sites transferred directly to the plaintiffs.
This matters for regular people because data brokers quietly profit from publishing your personal details — and the people most at risk are often those who most need privacy, like domestic violence survivors, law enforcement officers, and journalists. The Radaris case shows both that the legal tools to fight back exist, and that using them can take years of grinding effort. If you want your own data removed from broker sites, services like DeleteMe or Google's Results About You tool can help automate requests — because waiting for the courts isn't always an option.