HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control.
The malware has been used since fall 2023 against journalists, Iranian dissidents and people whose views oppose Iran’s government.
Victims were approached through messaging apps by people posing as familiar contacts or technical support, then sent files disguised as applications or services.
The campaign also relies on persuasive, context-specific decoys. Researchers at Group-IB identified 29 additional HEAVYGRAM samples, loaders and payloads while tracing this activity.
Their findings expand on U.S. government disclosures and link the operation to Handala Hack with moderate confidence, showing a surveillance effort built around social engineering and long-term access.
The impact reaches beyond a single infected computer. HEAVYGRAM can collect screenshots and audio, capture cached information, steal Telegram desktop data, run commands, add new payloads and delete files.
Group-IB said in a report shared with Cyber Security News (CSN) that the combination creates a risk for sources, private communications and sensitive work held by targeted people.
HEAVYGRAM Surveillance Malware
HEAVYGRAM’s operators use Telegram’s bot API to make an infected Windows machine check in, accept commands and send results back.
One configuration relies on a single bot while another uses two bots for check-ins, logging and delivery of later stages. The model can make malicious traffic look like routine web activity, a problem also seen in Telegram bot malware control campaigns.
After installation, the implant records the computer name and sends an initial beacon. It then sends a health message every 24 hours, letting operators see whether the device remains active.
Commands can start programs, collect system details, take screenshots, run secondary malware and exfiltrate Telegram Desktop files.
The attack begins with a convincing lure. First-stage files have posed as Pictory, KeePass and Telegram-related programs, with names chosen to look legitimate.
Some delivery chains use scripts or HTML applications, while others unpack embedded archives. This use of trusted-looking software mirrors trojanized messaging app installers used in other Windows attacks.

The implant also uses Windows registry entries to survive restarts. Associated CRUDEEXCLUDE samples may add security-exclusion paths before releasing HEAVYGRAM, giving the attackers another way to reduce the chance of detection.
Targeted Surveillance and Defense
The research connects HEAVYGRAM to a campaign aimed at people of interest to Iran, including a journalist at a UK-based Farsi-language news outlet and a U.S.-based victim described in public records.
The reported Handala link also fits the group’s wider history of coercive activity, including MOIS-linked destructive intrusions that have affected organizations in several countries.
A victim may see a decoy document or video while the malware retrieves a later stage and establishes persistence. Operators can later fetch attachments through Telegram, execute them on the host and use DLL side-loading, where a legitimate program loads a harmful companion file.
People at risk should install software only from official vendor sources and verify unexpected contacts through a separate trusted channel.

They should limit messaging-app privacy settings, treat unrequested files cautiously, and apply operating-system and security updates promptly. These steps are especially important when a message appears to come from a colleague or support team.
Organizations should isolate systems that match the indicators, review Windows autorun registry keys and review outbound bot API connections for Telegram backdoor delivery tactics.
Teams should identify unusual native-process launches, system folders with trailing spaces and unauthorized access to messaging data directories.
Application control can block binaries launched from APPDATA, ProgramData and other user-writable locations. Where Telegram is not an approved business tool, monitoring or blocking its API traffic can reduce exposure.
Code-signing checks and staff awareness training add useful layers, while threat teams should feed the indicators below into detection and response workflows.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd |
First-stage file |
| SHA-1 | 0190940243f6535f51d43edafac943d493159e14 |
First-stage file |
| MD5 | b3c1a3eebefafe1346c6a864b5423182 |
First-stage file |
| SHA-256 | 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 |
RAR archive artifact |
| SHA-1 | 88a8d118ee190ac36cf684c2992f6ddd2dda517b |
RAR archive artifact |
| MD5 | b2f6f40570ac9085b5463fdb623560de |
RAR archive artifact |
| SHA-256 | d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e |
HEAVYGRAM implant or backdoor |
| SHA-1 | 9108466c98df01033371483a789a0c23372c52f2 |
HEAVYGRAM implant or backdoor |
| MD5 | 16602375fc2dae1eb54580ab7eda6567 |
HEAVYGRAM implant or backdoor |
| SHA-256 | 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 |
Encrypted text artifact |
| SHA-1 | 53d41445e176bf53c5acd2dad533eda612b05855 |
Encrypted text artifact |
| MD5 | 7d3cce1f9dbaed585b61e6e903d69b9b |
Encrypted text artifact |
| SHA-256 | 6ddd145622cde2d2f91dace7e1f7edef22f4d49d3645fa9ad4bdb772829c30bf |
ZIP archive artifact |
| SHA-1 | 3549f6df9c14b70d2308b7b12033218e77fe1dc7 |
ZIP archive artifact |
| MD5 | d6756063230136f8c55ae27f1a4b0112 |
ZIP archive artifact |
| SHA-256 | 4a3aa8f4f0eb37be9778fbdf0b7dd282fc407557da61735d2ae9cfc73ee2aa81 |
First-stage file |
| SHA-1 | 9391928e5163ff791c1b4bc535f4ac92510810a6 |
First-stage file |
| MD5 | 5507a3e71aade582dd226b63b1930c56 |
First-stage file |
| SHA-256 | 844108a626c15395059efa355a66c8462af0c822d8219b35b6038d9d42dcf61d |
ZIP archive artifact |
| SHA-1 | ef3f7292cb2f91f9a34953b875eb018b3ef889d2 |
ZIP archive artifact |
| MD5 | ca65cc67247d0702ca34eb7b06873bec |
ZIP archive artifact |
| SHA-256 | 65359388b49ae2a982111ebe8ac837d0f3294ceab7a712df20d0f6c19bf3029e |
HEAVYGRAM implant or backdoor |
| SHA-1 | 4a2658c66f3aeabdb05f56ba88d587683319ce6d |
HEAVYGRAM implant or backdoor |
| MD5 | 4dcfa4317f2111109cd41f457541ed2b |
HEAVYGRAM implant or backdoor |
| SHA-256 | ec9d3e32a4e78f8cc9581f5cf030f0594debee1ce67d2d0759aff3ec1c720b35 |
ZIP archive artifact |
| SHA-1 | 5d3cde9f6971ec35431cbb113b6b4bc292ea5db0 |
ZIP archive artifact |
| MD5 | a1ca53f09b0c6fe3b3b57b5202192d60 |
ZIP archive artifact |
| SHA-256 | 5380ffda12f97cf4d8e0fe02e0580aa1a48b4b6da95e7f8a30029ad125c51b3f |
HEAVYGRAM implant or backdoor |
| SHA-1 | 2b11bccdea89d428610c15bea1fba417ab8681a6 |
HEAVYGRAM implant or backdoor |
| MD5 | b66bd18de204d405500dc079876b7cbf |
HEAVYGRAM implant or backdoor |
| SHA-256 | e9d2e4e8fac6420ca3b3a3a63a3d313dcfb236a24a11889d6923dd9b42a777d4 |
First-stage file |
| SHA-1 | 6d9817f5066be757f5f09b067a80fed3cfe280f6 |
First-stage file |
| MD5 | 14698d3a03216daa2cf6f39e4f1c4031 |
First-stage file |
| SHA-256 | 8ad63d4d30cd28391318e26f4e9464f302b0a12675a721967d4f2173ed6cfe8a |
First-stage file |
| SHA-1 | af9d13e27c8eedc30dd78f237013b239cf23f35d |
First-stage file |
| MD5 | 0a656287defcbd8a9c47385b805993df |
First-stage file |
| SHA-256 | 3f1313c813e51edf5734d9fb99eb93d6c3aa6c309e3f0a6a4878291c5b2ec73b |
ZIP archive artifact |
| SHA-1 | f269488e2128128f234ee2e996489317bfa4720b |
ZIP archive artifact |
| MD5 | d9418fb432631021a15fb896b365d608 |
ZIP archive artifact |
| SHA-256 | 138a4c9cd617912c2269fae64b6b12d57e926a36c2c62f25ee05a32cdf102212 |
HEAVYGRAM implant or backdoor |
| SHA-1 | 8c6b6236420c876989af36e3a9e648a00f3000c9 |
HEAVYGRAM implant or backdoor |
| MD5 | fefaefbf09841cef739d090305edc7a4 |
HEAVYGRAM implant or backdoor |
| SHA-256 | bb56792212abe160fff643631fb69b2081601e6310fc6669fd9d52d690ec1903 |
HEAVYGRAM implant or backdoor |
| SHA-1 | 6fcf829720f425f81a6b35ac5f05fa94775429eb |
HEAVYGRAM implant or backdoor |
| MD5 | c8aeca21d10f6bbb78e1f2a67d78fcad |
HEAVYGRAM implant or backdoor |
| SHA-256 | 7477f4f25d1cfc3dfb1267e35ab4bcf0b30b8c7ec9677a8d1849ee7d17bc15aa |
ZIP archive artifact |
| SHA-1 | 168caccbe59473091aa4fbbebba6257aed17985e |
ZIP archive artifact |
| MD5 | 87f7d0b30f7905d282fb464f5ad6c6cf |
ZIP archive artifact |
| SHA-256 | 2deeeda412c40ad515dca940916a376d187219ed09ed697b4be4879b7091ec53 |
CRUDEEXCLUDE executable |
| SHA-1 | 5dd86e22b882d52c67d274e3297694009d13fb96 |
CRUDEEXCLUDE executable |
| MD5 | 6cae314ddcd821dd2a60dff1fa02460a |
CRUDEEXCLUDE executable |
| SHA-256 | b0308c91a56209222b178e7099ee03a7b0d06a0e473f042fb2d3c144a07484fa |
ZIP archive artifact |
| SHA-1 | 88816b1262eaf819edebb93dc883b3082cc64c34 |
ZIP archive artifact |
| MD5 | be98163e7fea224af382a2251252ce4d |
ZIP archive artifact |
| SHA-256 | c9e5cbc98e91aa35a260a1f85d7a5605dc7aa8d2d0b71eb6f063147d4dfa1b5f |
HEAVYGRAM implant or backdoor |
| SHA-1 | fec45095576d13a20a6d42096fcadc2d8f6dddd8 |
HEAVYGRAM implant or backdoor |
| MD5 | 970fc0fcf3bc5a933d10e8413536f27f |
HEAVYGRAM implant or backdoor |
| SHA-256 | d40d730bcfa4cc7f1ee070f6ce863b03acb81af0a4d66feaec285e1205258b35 |
First-stage file |
| SHA-1 | 33e9e5463c12c0a21a7ab37fb7496ab2c5c40bb4 |
First-stage file |
| MD5 | 5f3271ba8840be547b1f3a42ea28ebe0 |
First-stage file |
| SHA-256 | 067d93741bcab16810ef15c11941245229519470dc7b24793dd1d3a7addacaae |
Encrypted text artifact |
| SHA-1 | 2fa0eb74f8a527d938f8538d66bcdebcc9771527 |
Encrypted text artifact |
| MD5 | a3394ef7ffa7e88b2e7efaee4617fe04 |
Encrypted text artifact |
| SHA-256 | cbe9e32393529cd79e19a639a1d2da93fba06082be2bdb0c04241f269f98c773 |
ZIP archive artifact |
| SHA-1 | ba3874ca96f9bca1daff22ef49ea7505d52b40d4 |
ZIP archive artifact |
| MD5 | 94779909cc510194900c3cc17d1194c8 |
ZIP archive artifact |
| SHA-256 | 4a3b003994112b4dd24ac8b9cc4757f4a12576b57b3cc8f5028d85fbceb7c405 |
HEAVYGRAM implant or backdoor |
| SHA-1 | 0fe3cf4cabadedb382b0833dcb6ba74db3242022 |
HEAVYGRAM implant or backdoor |
| MD5 | 7e23ffadb664b0e53d821478a249d84c |
HEAVYGRAM implant or backdoor |
| SHA-256 | e8b633dcad173eb41ef02686b46779a4a0e53df7f6c63039a798f2db5eb83afc |
CRUDEEXCLUDE executable |
| SHA-1 | 704119320f7ed10dc7707833218468d455d3c5fd |
CRUDEEXCLUDE executable |
| MD5 | 1e6b601f733bc40eaa58916986bfc5b9 |
CRUDEEXCLUDE executable |
| SHA-256 | ffceb438127725a6a664aba5021f7625bd8c22b3f76447de91b728839136c9c3 |
First-stage file |
| SHA-1 | 7ee579a1fa697f66d80103a867cf706f67bba32b |
First-stage file |
| MD5 | 1d947084fdf25e07ec8bcdaf0cec508a |
First-stage file |
| SHA-256 | 0d74156089292eee308017c8e8a7550739ecb6149ff379810f7c54b1dbaabc91 |
HEAVYGRAM implant or backdoor |
| SHA-1 | 87dcba4957396a9e594ed1d133bc115315763002 |
HEAVYGRAM implant or backdoor |
| MD5 | e51ff37fb431767dcdec0b5e6d2a786a |
HEAVYGRAM implant or backdoor |
| SHA-256 | 886d04b78017f721ed458158e3c31300cb7f9d512481a50f21461711438e1c5e |
RAR archive artifact |
| SHA-1 | ac5939a17ec6455b6b7ae0f04c5b71b1db0d00c5 |
RAR archive artifact |
| MD5 | 42215c1fb55d945b4d2a0bb188ca4dcf |
RAR archive artifact |
| SHA-256 | 2640fc95373dd299cc61966c2df5ba9e013280ee02944d11bb4d1f70ee57aa30 |
ZIP archive artifact |
| SHA-1 | 44068866546ffea6ef8ab8a639c2151b13f9fd6e |
ZIP archive artifact |
| MD5 | cbe1743e9aebd3e3002b2b005deb332c |
ZIP archive artifact |
| SHA-256 | 58fb875fedf57055c3fedf59fdedb9ebffbf452a0f7f21608abb069cc13effb9 |
Decoy RTF file |
| SHA-1 | ea7071abca429f28bfe629a913513c6d604771f4 |
Decoy RTF file |
| MD5 | 4dd0cbdad60e65fb8cd6999bd9359444 |
Decoy RTF file |
| SHA-256 | c4e194747d9a268ff56ac1f0708745cbcc164751dcaa24f1a5a15acbe9c4d998 |
First-stage file |
| SHA-1 | 43d9af0c411110905ab4ddf4e4f713101c74d9de |
First-stage file |
| MD5 | 8e9e81d1b252d7fa99579e9cf2e4b4ba |
First-stage file |
| SHA-256 | a85ce7dde7f83f116436adbdaa8e782e3af0f0ce87ec6534ec7b8ea83bb33eed |
Decoy MP4 file |
| SHA-1 | 292887ea4406fce26773992af0bd7dc34951aa84 |
Decoy MP4 file |
| MD5 | 66fd60d03613decacc3c42d94dd9aab8 |
Decoy MP4 file |
| SHA-256 | 0aee700463efe5155d816b0f4d44edc9f4b4579156159b361d1f663b4143c4fd |
CRUDEEXCLUDE executable |
| SHA-1 | 5f899031ec31431ff0f5fcaf4ccf5cd9484b2066 |
CRUDEEXCLUDE executable |
| MD5 | 26892452f724581530c45287c8b7bc67 |
CRUDEEXCLUDE executable |
| MD5 | B9086413E7B6A0C6A11C25D14C22615F |
First-stage file |
| MD5 | 7402F2F9263782A4C469570035843510 |
First-stage file |
| MD5 | EBDD9595B79B39F53909D862499DBC94 |
Second-stage file |
| MD5 | F8B5554808428291ACC65D1FD2EFE01C |
DLL utility |
| MD5 | 481C5B5E69A08C3DF206C59FD8DDC0DC |
Second-stage file |
| MD5 | 2965817D063F1E8F9889F9126443D631 |
Encrypted text artifact |
| MD5 | D70EBF20E3D697897BAD5BEBF72EA271 |
Second-stage file |
| MD5 | 3E7A2FCEF1D038D05B20148C573A6499 |
Second-stage file |
| SHA-256 | 65e2dbe5c6b670f663d93fd65608470091a231803b4f449bb00e99ebf76eddb7 |
First-stage file |
| SHA-1 | 6dd639542464a647e3816af896fb1320aff64ba5 |
First-stage file |
| MD5 | 602174f6e691d6845ac645b68f1f2538 |
First-stage file |
| URL | hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptx |
Decoy document download location |
| URL | hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/efg_d4[.]zip |
ZIP archive download location |
| URL | hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4 |
Decoy video download location |
| URL | hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_def7[.]zip |
ZIP archive download location |
| URL | hxxps://sgp1[.]vultrobjects[.]com/downloads/pictory/Pictory_premium_ver9.0.4.exe |
Malicious executable download location |
| URL | hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_17[.]zip |
ZIP archive download location |
| URL | hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4 |
Decoy video download location |
| URL | hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe |
Malicious executable download location |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The post Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware appeared first on Cyber Security News.
