HEAVYGRAM Malware Uses Telegram for Covert Command and Control
A sophisticated surveillance backdoor named HEAVYGRAM has been discovered weaponizing Telegram for command and control, targeting journalists and dissidents opposing Iran's government since late 2023.

A new and concerning surveillance backdoor, dubbed HEAVYGRAM, has been identified by researchers, which ingeniously leverages the popular messaging platform Telegram to serve as its command-and-control (C2) infrastructure. This tactic allows attackers to bypass traditional C2 servers, making detection and disruption significantly more challenging. The malware has been actively deployed since the latter half of 2023, primarily targeting individuals such as journalists and dissidents who hold views contrary to the Iranian government.
The operational methodology of HEAVYGRAM involves using Telegram bots, accounts, and groups to receive instructions from its operators and to exfiltrate stolen data. This approach cleverly disguises malicious traffic as legitimate user activity on Telegram, a platform widely used for communication. The malware's capabilities are extensive, including the ability to steal Telegram desktop data, capture screenshots and audio recordings, execute arbitrary commands on infected systems, deploy additional payloads, and even delete files, posing a severe risk to sensitive communications and confidential information.
Researchers at Group-IB have expanded upon initial disclosures by identifying 29 additional HEAVYGRAM samples, loaders, and payloads. Their analysis suggests a moderate confidence link between this operation and the Handala Hack group, indicating a coordinated surveillance effort focused on social engineering and establishing long-term access to target systems. The campaign employs sophisticated social engineering tactics, with victims being approached through messaging apps by individuals posing as trusted contacts or technical support personnel.
Attackers deliver malicious files disguised as legitimate applications or services, often using convincing, context-specific decoys to lure victims into execution. These decoys have included files masquerading as well-known software like Pictory, KeePass, and even Telegram-related applications. Some attack chains utilize scripts or HTML applications for delivery, while others rely on embedded archives that require unpacking, mirroring trojanized installers seen in other Windows-based attacks.
Once installed, the HEAVYGRAM implant establishes persistence by creating Windows registry entries, ensuring it survives system reboots. Associated CRUDEEXCLUDE samples may also be deployed to add security exclusion paths, further reducing the likelihood of detection by antivirus software. The malware establishes a regular check-in mechanism, sending an initial beacon upon infection and a subsequent health message every 24 hours to confirm the device's active status.
Operators can remotely issue commands to start programs, gather system details, capture screenshots, deploy secondary malware, and exfiltrate sensitive data, including files from the Telegram Desktop application. The use of DLL side-loading, where a legitimate program is tricked into loading a malicious companion file, is another technique employed to maintain stealth and operational effectiveness.
The implications of HEAVYGRAM are far-reaching, particularly for individuals involved in sensitive reporting or activism. The ability to steal Telegram data, capture communications, and maintain persistent access creates a significant threat to source protection, private conversations, and the integrity of sensitive work. The connection to groups with a history of coercive activities further underscores the severity of this surveillance campaign.
To mitigate the risks associated with HEAVYGRAM and similar threats, users are advised to download software exclusively from official vendor sources, verify unexpected contacts through separate trusted channels, and exercise extreme caution with unrequested files. Implementing strong messaging app privacy settings, promptly applying operating system and security updates, and being wary of urgent-sounding notifications are crucial defensive measures. Organizations should also monitor for indicators of compromise, review system configurations, and consider blocking Telegram's API traffic if it is not an approved business tool.