Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control.

The malware has been used since fall 2023 against journalists, Iranian dissidents and people whose views oppose Iran’s government.

Victims were approached through messaging apps by people posing as familiar contacts or technical support, then sent files disguised as applications or services.

The campaign also relies on persuasive, context-specific decoys. Researchers at Group-IB identified 29 additional HEAVYGRAM samples, loaders and payloads while tracing this activity.

Their findings expand on U.S. government disclosures and link the operation to Handala Hack with moderate confidence, showing a surveillance effort built around social engineering and long-term access.

The impact reaches beyond a single infected computer. HEAVYGRAM can collect screenshots and audio, capture cached information, steal Telegram desktop data, run commands, add new payloads and delete files.

Group-IB said in a report shared with Cyber Security News (CSN) that the combination creates a risk for sources, private communications and sensitive work held by targeted people.

HEAVYGRAM Surveillance Malware

HEAVYGRAM’s operators use Telegram’s bot API to make an infected Windows machine check in, accept commands and send results back.

One configuration relies on a single bot while another uses two bots for check-ins, logging and delivery of later stages. The model can make malicious traffic look like routine web activity, a problem also seen in Telegram bot malware control campaigns.

After installation, the implant records the computer name and sends an initial beacon. It then sends a health message every 24 hours, letting operators see whether the device remains active.

Commands can start programs, collect system details, take screenshots, run secondary malware and exfiltrate Telegram Desktop files.

The attack begins with a convincing lure. First-stage files have posed as Pictory, KeePass and Telegram-related programs, with names chosen to look legitimate.

Some delivery chains use scripts or HTML applications, while others unpack embedded archives. This use of trusted-looking software mirrors trojanized messaging app installers used in other Windows attacks.

HEAVYGRAM killchain (Source - Group-IB)
HEAVYGRAM killchain (Source – Group-IB)

The implant also uses Windows registry entries to survive restarts. Associated CRUDEEXCLUDE samples may add security-exclusion paths before releasing HEAVYGRAM, giving the attackers another way to reduce the chance of detection.

Targeted Surveillance and Defense

The research connects HEAVYGRAM to a campaign aimed at people of interest to Iran, including a journalist at a UK-based Farsi-language news outlet and a U.S.-based victim described in public records.

The reported Handala link also fits the group’s wider history of coercive activity, including MOIS-linked destructive intrusions that have affected organizations in several countries.

A victim may see a decoy document or video while the malware retrieves a later stage and establishes persistence. Operators can later fetch attachments through Telegram, execute them on the host and use DLL side-loading, where a legitimate program loads a harmful companion file.

People at risk should install software only from official vendor sources and verify unexpected contacts through a separate trusted channel.

Press release announcing the seizure of MOIS-linked domains (Source - Group-IB)
Press release announcing the seizure of MOIS-linked domains (Source – Group-IB)

They should limit messaging-app privacy settings, treat unrequested files cautiously, and apply operating-system and security updates promptly. These steps are especially important when a message appears to come from a colleague or support team.

Organizations should isolate systems that match the indicators, review Windows autorun registry keys and review outbound bot API connections for Telegram backdoor delivery tactics.

Teams should identify unusual native-process launches, system folders with trailing spaces and unauthorized access to messaging data directories.

Application control can block binaries launched from APPDATA, ProgramData and other user-writable locations. Where Telegram is not an approved business tool, monitoring or blocking its API traffic can reduce exposure.

Code-signing checks and staff awareness training add useful layers, while threat teams should feed the indicators below into detection and response workflows.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd First-stage file
SHA-1 0190940243f6535f51d43edafac943d493159e14 First-stage file
MD5 b3c1a3eebefafe1346c6a864b5423182 First-stage file
SHA-256 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 RAR archive artifact
SHA-1 88a8d118ee190ac36cf684c2992f6ddd2dda517b RAR archive artifact
MD5 b2f6f40570ac9085b5463fdb623560de RAR archive artifact
SHA-256 d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e HEAVYGRAM implant or backdoor
SHA-1 9108466c98df01033371483a789a0c23372c52f2 HEAVYGRAM implant or backdoor
MD5 16602375fc2dae1eb54580ab7eda6567 HEAVYGRAM implant or backdoor
SHA-256 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 Encrypted text artifact
SHA-1 53d41445e176bf53c5acd2dad533eda612b05855 Encrypted text artifact
MD5 7d3cce1f9dbaed585b61e6e903d69b9b Encrypted text artifact
SHA-256 6ddd145622cde2d2f91dace7e1f7edef22f4d49d3645fa9ad4bdb772829c30bf ZIP archive artifact
SHA-1 3549f6df9c14b70d2308b7b12033218e77fe1dc7 ZIP archive artifact
MD5 d6756063230136f8c55ae27f1a4b0112 ZIP archive artifact
SHA-256 4a3aa8f4f0eb37be9778fbdf0b7dd282fc407557da61735d2ae9cfc73ee2aa81 First-stage file
SHA-1 9391928e5163ff791c1b4bc535f4ac92510810a6 First-stage file
MD5 5507a3e71aade582dd226b63b1930c56 First-stage file
SHA-256 844108a626c15395059efa355a66c8462af0c822d8219b35b6038d9d42dcf61d ZIP archive artifact
SHA-1 ef3f7292cb2f91f9a34953b875eb018b3ef889d2 ZIP archive artifact
MD5 ca65cc67247d0702ca34eb7b06873bec ZIP archive artifact
SHA-256 65359388b49ae2a982111ebe8ac837d0f3294ceab7a712df20d0f6c19bf3029e HEAVYGRAM implant or backdoor
SHA-1 4a2658c66f3aeabdb05f56ba88d587683319ce6d HEAVYGRAM implant or backdoor
MD5 4dcfa4317f2111109cd41f457541ed2b HEAVYGRAM implant or backdoor
SHA-256 ec9d3e32a4e78f8cc9581f5cf030f0594debee1ce67d2d0759aff3ec1c720b35 ZIP archive artifact
SHA-1 5d3cde9f6971ec35431cbb113b6b4bc292ea5db0 ZIP archive artifact
MD5 a1ca53f09b0c6fe3b3b57b5202192d60 ZIP archive artifact
SHA-256 5380ffda12f97cf4d8e0fe02e0580aa1a48b4b6da95e7f8a30029ad125c51b3f HEAVYGRAM implant or backdoor
SHA-1 2b11bccdea89d428610c15bea1fba417ab8681a6 HEAVYGRAM implant or backdoor
MD5 b66bd18de204d405500dc079876b7cbf HEAVYGRAM implant or backdoor
SHA-256 e9d2e4e8fac6420ca3b3a3a63a3d313dcfb236a24a11889d6923dd9b42a777d4 First-stage file
SHA-1 6d9817f5066be757f5f09b067a80fed3cfe280f6 First-stage file
MD5 14698d3a03216daa2cf6f39e4f1c4031 First-stage file
SHA-256 8ad63d4d30cd28391318e26f4e9464f302b0a12675a721967d4f2173ed6cfe8a First-stage file
SHA-1 af9d13e27c8eedc30dd78f237013b239cf23f35d First-stage file
MD5 0a656287defcbd8a9c47385b805993df First-stage file
SHA-256 3f1313c813e51edf5734d9fb99eb93d6c3aa6c309e3f0a6a4878291c5b2ec73b ZIP archive artifact
SHA-1 f269488e2128128f234ee2e996489317bfa4720b ZIP archive artifact
MD5 d9418fb432631021a15fb896b365d608 ZIP archive artifact
SHA-256 138a4c9cd617912c2269fae64b6b12d57e926a36c2c62f25ee05a32cdf102212 HEAVYGRAM implant or backdoor
SHA-1 8c6b6236420c876989af36e3a9e648a00f3000c9 HEAVYGRAM implant or backdoor
MD5 fefaefbf09841cef739d090305edc7a4 HEAVYGRAM implant or backdoor
SHA-256 bb56792212abe160fff643631fb69b2081601e6310fc6669fd9d52d690ec1903 HEAVYGRAM implant or backdoor
SHA-1 6fcf829720f425f81a6b35ac5f05fa94775429eb HEAVYGRAM implant or backdoor
MD5 c8aeca21d10f6bbb78e1f2a67d78fcad HEAVYGRAM implant or backdoor
SHA-256 7477f4f25d1cfc3dfb1267e35ab4bcf0b30b8c7ec9677a8d1849ee7d17bc15aa ZIP archive artifact
SHA-1 168caccbe59473091aa4fbbebba6257aed17985e ZIP archive artifact
MD5 87f7d0b30f7905d282fb464f5ad6c6cf ZIP archive artifact
SHA-256 2deeeda412c40ad515dca940916a376d187219ed09ed697b4be4879b7091ec53 CRUDEEXCLUDE executable
SHA-1 5dd86e22b882d52c67d274e3297694009d13fb96 CRUDEEXCLUDE executable
MD5 6cae314ddcd821dd2a60dff1fa02460a CRUDEEXCLUDE executable
SHA-256 b0308c91a56209222b178e7099ee03a7b0d06a0e473f042fb2d3c144a07484fa ZIP archive artifact
SHA-1 88816b1262eaf819edebb93dc883b3082cc64c34 ZIP archive artifact
MD5 be98163e7fea224af382a2251252ce4d ZIP archive artifact
SHA-256 c9e5cbc98e91aa35a260a1f85d7a5605dc7aa8d2d0b71eb6f063147d4dfa1b5f HEAVYGRAM implant or backdoor
SHA-1 fec45095576d13a20a6d42096fcadc2d8f6dddd8 HEAVYGRAM implant or backdoor
MD5 970fc0fcf3bc5a933d10e8413536f27f HEAVYGRAM implant or backdoor
SHA-256 d40d730bcfa4cc7f1ee070f6ce863b03acb81af0a4d66feaec285e1205258b35 First-stage file
SHA-1 33e9e5463c12c0a21a7ab37fb7496ab2c5c40bb4 First-stage file
MD5 5f3271ba8840be547b1f3a42ea28ebe0 First-stage file
SHA-256 067d93741bcab16810ef15c11941245229519470dc7b24793dd1d3a7addacaae Encrypted text artifact
SHA-1 2fa0eb74f8a527d938f8538d66bcdebcc9771527 Encrypted text artifact
MD5 a3394ef7ffa7e88b2e7efaee4617fe04 Encrypted text artifact
SHA-256 cbe9e32393529cd79e19a639a1d2da93fba06082be2bdb0c04241f269f98c773 ZIP archive artifact
SHA-1 ba3874ca96f9bca1daff22ef49ea7505d52b40d4 ZIP archive artifact
MD5 94779909cc510194900c3cc17d1194c8 ZIP archive artifact
SHA-256 4a3b003994112b4dd24ac8b9cc4757f4a12576b57b3cc8f5028d85fbceb7c405 HEAVYGRAM implant or backdoor
SHA-1 0fe3cf4cabadedb382b0833dcb6ba74db3242022 HEAVYGRAM implant or backdoor
MD5 7e23ffadb664b0e53d821478a249d84c HEAVYGRAM implant or backdoor
SHA-256 e8b633dcad173eb41ef02686b46779a4a0e53df7f6c63039a798f2db5eb83afc CRUDEEXCLUDE executable
SHA-1 704119320f7ed10dc7707833218468d455d3c5fd CRUDEEXCLUDE executable
MD5 1e6b601f733bc40eaa58916986bfc5b9 CRUDEEXCLUDE executable
SHA-256 ffceb438127725a6a664aba5021f7625bd8c22b3f76447de91b728839136c9c3 First-stage file
SHA-1 7ee579a1fa697f66d80103a867cf706f67bba32b First-stage file
MD5 1d947084fdf25e07ec8bcdaf0cec508a First-stage file
SHA-256 0d74156089292eee308017c8e8a7550739ecb6149ff379810f7c54b1dbaabc91 HEAVYGRAM implant or backdoor
SHA-1 87dcba4957396a9e594ed1d133bc115315763002 HEAVYGRAM implant or backdoor
MD5 e51ff37fb431767dcdec0b5e6d2a786a HEAVYGRAM implant or backdoor
SHA-256 886d04b78017f721ed458158e3c31300cb7f9d512481a50f21461711438e1c5e RAR archive artifact
SHA-1 ac5939a17ec6455b6b7ae0f04c5b71b1db0d00c5 RAR archive artifact
MD5 42215c1fb55d945b4d2a0bb188ca4dcf RAR archive artifact
SHA-256 2640fc95373dd299cc61966c2df5ba9e013280ee02944d11bb4d1f70ee57aa30 ZIP archive artifact
SHA-1 44068866546ffea6ef8ab8a639c2151b13f9fd6e ZIP archive artifact
MD5 cbe1743e9aebd3e3002b2b005deb332c ZIP archive artifact
SHA-256 58fb875fedf57055c3fedf59fdedb9ebffbf452a0f7f21608abb069cc13effb9 Decoy RTF file
SHA-1 ea7071abca429f28bfe629a913513c6d604771f4 Decoy RTF file
MD5 4dd0cbdad60e65fb8cd6999bd9359444 Decoy RTF file
SHA-256 c4e194747d9a268ff56ac1f0708745cbcc164751dcaa24f1a5a15acbe9c4d998 First-stage file
SHA-1 43d9af0c411110905ab4ddf4e4f713101c74d9de First-stage file
MD5 8e9e81d1b252d7fa99579e9cf2e4b4ba First-stage file
SHA-256 a85ce7dde7f83f116436adbdaa8e782e3af0f0ce87ec6534ec7b8ea83bb33eed Decoy MP4 file
SHA-1 292887ea4406fce26773992af0bd7dc34951aa84 Decoy MP4 file
MD5 66fd60d03613decacc3c42d94dd9aab8 Decoy MP4 file
SHA-256 0aee700463efe5155d816b0f4d44edc9f4b4579156159b361d1f663b4143c4fd CRUDEEXCLUDE executable
SHA-1 5f899031ec31431ff0f5fcaf4ccf5cd9484b2066 CRUDEEXCLUDE executable
MD5 26892452f724581530c45287c8b7bc67 CRUDEEXCLUDE executable
MD5 B9086413E7B6A0C6A11C25D14C22615F First-stage file
MD5 7402F2F9263782A4C469570035843510 First-stage file
MD5 EBDD9595B79B39F53909D862499DBC94 Second-stage file
MD5 F8B5554808428291ACC65D1FD2EFE01C DLL utility
MD5 481C5B5E69A08C3DF206C59FD8DDC0DC Second-stage file
MD5 2965817D063F1E8F9889F9126443D631 Encrypted text artifact
MD5 D70EBF20E3D697897BAD5BEBF72EA271 Second-stage file
MD5 3E7A2FCEF1D038D05B20148C573A6499 Second-stage file
SHA-256 65e2dbe5c6b670f663d93fd65608470091a231803b4f449bb00e99ebf76eddb7 First-stage file
SHA-1 6dd639542464a647e3816af896fb1320aff64ba5 First-stage file
MD5 602174f6e691d6845ac645b68f1f2538 First-stage file
URL hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptx Decoy document download location
URL hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/efg_d4[.]zip ZIP archive download location
URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4 Decoy video download location
URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_def7[.]zip ZIP archive download location
URL hxxps://sgp1[.]vultrobjects[.]com/downloads/pictory/Pictory_premium_ver9.0.4.exe Malicious executable download location
URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_17[.]zip ZIP archive download location
URL hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4 Decoy video download location
URL hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe Malicious executable download location

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware appeared first on Cyber Security News.