Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
FBI Dismantles NightmareStresser DDoS Service
September 17, 2026
Critical BIND 9 Vulnerabilities Allow Cache Poisoning, DoS
September 17, 2026
CISA Urges Defenders to Deploy Deception Technologies
September 17, 2026
Home/CyberSecurity News/HEAVYGRAM Malware Uses Telegram as Command and Control Server
CyberSecurity News

HEAVYGRAM Malware Uses Telegram as Command and Control Server

Key Takeaways HEAVYGRAM is a Windows surveillance backdoor that leverages Telegram’s infrastructure for command and control. The malware has been actively used since late 2023, primarily...

Marcus Rodriguez
Marcus Rodriguez
September 17, 2026 4 Min Read
3 0

Key Takeaways

  • HEAVYGRAM is a Windows surveillance backdoor that leverages Telegram’s infrastructure for command and control.
  • The malware has been actively used since late 2023, primarily targeting journalists, Iranian dissidents, and individuals critical of the Iranian government.
  • Initial infection typically occurs through social engineering tactics, where victims receive malicious files disguised as legitimate applications or support documents via messaging apps.
  • HEAVYGRAM is capable of extensive data exfiltration, including screenshots, audio recordings, cached information, and Telegram Desktop data.
  • The operation shows moderate confidence links to the Handala Hack group, indicating a sophisticated, long-term surveillance effort.

HEAVYGRAM: A New Era of Telegram-Based Surveillance

A sophisticated Windows surveillance backdoor, dubbed HEAVYGRAM, has emerged, transforming the popular messaging application Telegram into a covert command and control (C2) hub for malicious operations. Instead of relying on traditional, dedicated C2 servers, HEAVYGRAM exploits Telegram’s native features—bots, accounts, and groups—to receive instructions, exfiltrate stolen data, and maintain persistent control over compromised systems.

Table Of Content

  • Key Takeaways
  • HEAVYGRAM: A New Era of Telegram-Based Surveillance
  • The Pervasive Reach of HEAVYGRAM
  • Technical Modus Operandi
  • Targeted Surveillance and Defense
  • What You Should Do

Since its observed deployment in the fall of 2023, HEAVYGRAM has been strategically aimed at high-value targets, including journalists, Iranian dissidents, and individuals expressing views contrary to the Iranian government. Attackers initiate contact through messaging platforms, impersonating trusted contacts or technical support personnel, and then deliver malicious files disguised as legitimate applications or services.

Researchers at Group-IB have significantly expanded our understanding of this campaign. Their analysis uncovered 29 additional HEAVYGRAM samples, loaders, and payloads, tracing the intricate web of activity. These findings build upon earlier U.S. government disclosures and suggest a moderate confidence link between this operation and the Handala Hack group. The overall effort underscores a persistent surveillance campaign heavily reliant on social engineering and designed for prolonged access to victim systems.

The Pervasive Reach of HEAVYGRAM

The impact of HEAVYGRAM extends far beyond a single compromised machine. The malware possesses a broad array of capabilities, enabling it to collect screenshots and audio recordings, capture cached system information, steal sensitive data from Telegram Desktop installations, execute arbitrary commands, deploy additional payloads, and delete files. Group-IB said in a report, this comprehensive data collection poses significant risks to sources, private communications, and sensitive work handled by targeted individuals, highlighting the severe implications of such a breach.

Technical Modus Operandi

HEAVYGRAM operators leverage Telegram’s Bot API to establish communication with infected Windows machines. This allows compromised systems to “check in,” receive commands, and transmit results back to the attackers. Some configurations utilize a single bot for these interactions, while more complex setups employ two bots for initial check-ins, logging, and the delivery of subsequent stages of the attack. This method helps obfuscate malicious traffic, making it appear as routine web activity, a tactic also observed in other Telegram bot-controlled malware campaigns.

Upon successful installation, the HEAVYGRAM implant registers the compromised computer’s name and sends an initial beacon to the C2. A “health message” is then transmitted every 24 hours, allowing operators to monitor the device’s activity status. The malware supports a range of commands, including launching programs, gathering system details, capturing screenshots, deploying secondary malware, and exfiltrating Telegram Desktop files.

The initial phase of the attack is characterized by highly convincing lures. First-stage malicious files have been observed masquerading as legitimate software such as Pictory, KeePass, and various Telegram-related programs, with filenames carefully chosen to appear authentic. Attack chains vary, sometimes involving scripts or HTML applications, while others unpack embedded archives. This strategy of employing trusted-looking software mirrors the use of trojanized messaging app installers seen in other Windows-based attacks.

For persistence across system restarts, the HEAVYGRAM implant modifies Windows registry entries. Furthermore, associated CRUDEEXCLUDE samples have been identified, which may establish security exclusion paths before deploying HEAVYGRAM. This pre-emptive action provides attackers with an additional layer of defense against detection by endpoint security solutions.

Targeted Surveillance and Defense

The recent research definitively links HEAVYGRAM to a targeted surveillance campaign against individuals of interest to the Iranian government. This includes a journalist working for a UK-based Farsi-language news outlet and a U.S.-based victim documented in public records. The reported connection to the Handala Hack group aligns with the group’s established history of coercive activities, which encompass destructive intrusions linked to the Iranian Ministry of Intelligence and Security (MOIS) that have impacted organizations across multiple countries.

During an attack, victims may encounter a decoy document or video while the malware covertly retrieves subsequent stages and establishes persistence. Operators can then retrieve additional attachments via Telegram, execute them on the host system, and even employ DLL side-loading techniques, where a legitimate program is tricked into loading a malicious companion file.

What You Should Do

  • Exercise Caution with Downloads: Only install software from official vendor sources. Verify any unexpected contacts or requests for software installation through a separate, trusted communication channel.
  • Review Messaging App Settings: Limit privacy settings on messaging applications to reduce exposure. Treat all unrequested files with extreme caution, regardless of the sender.
  • Maintain System Updates: Promptly apply all operating system and security updates to patch known vulnerabilities. This is especially crucial when messages appear to originate from colleagues or IT support.
  • Implement Application Control: Organizations should use application control solutions to block binaries launched from user-writable locations like APPDATA and ProgramData.
  • Monitor Telegram API Traffic: If Telegram is not an approved business tool, monitor or block its API traffic to reduce potential exposure to C2 communications.
  • Enhance Staff Awareness: Conduct regular staff awareness training on social engineering tactics, phishing, and the risks associated with unexpected files and links.
  • Integrate IoCs: Feed the provided Indicators of Compromise (IoCs) into your organization’s detection and response workflows to identify and mitigate potential HEAVYGRAM infections.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Thai College Website Redirects Google Users to Illegal Online Casino

Next Post

SilkParasite Malware Infrastructure Active for Four Years in Central Asia

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Thai College Website Redirects Google Users to Illegal Online Casino
September 17, 2026
North Korean IT workers exploit AI, remote tools to fake interviews
September 17, 2026
Critical Docker Sandbox Vulnerabilities Let Guests Escape microVMs
September 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us