HEAVYGRAM killchain | Image: Group-IB
At a Glance
| Attribute | Details |
|---|---|
| Malware Family | HEAVYGRAM (associated with CRUDEEXCLUDE) |
| Threat Actor | Handala Hack (suspected persona of Void Manticore / MOIS) |
| Target Victims | Iranian dissidents, Farsi-language journalists, and academic targets |
| Delivery Vector | Social engineering, malicious scripts, and trojanized installers |
| Key Capabilities | Screen recording, Telegram session theft, remote command execution |
| Source | Group-IB Threat Intelligence |
Executive Summary
Security researchers discovered 29 new samples of the HEAVYGRAM malware targeting dissidents and reporters. The multi-stage implant abuses Telegram channels for stealthy command execution and data exfiltration. Government agencies and private analysts link this campaign to suspected Iranian state-backed cyber operations.
Delivery and Social Engineering Tactics
Attackers distribute the first stage of the malware through messaging applications. Specifically, threat actors pose as trusted contacts or technical support agents to deceive targeted victims. They send malicious archives disguised as legitimate software like Telegram, KeePass, or video editors.
In another delivery track, the operators deploy Windows Script Files and HTML applications. For example, attackers send decoy presentation files stored on cloud object storage services. These scripts check system disk capacity before launching malicious PowerShell commands. If the primary drive volume exceeds 50 gigabytes, the script downloads secondary stages.
Furthermore, the campaign delivering the HEAVYGRAM malware uses Windows screensavers with Persian filenames. One sample masqueraded as an academic list of expelled university students. The file contained an embedded archive that extracted executable files to disk. In addition, Delphi executables known as CRUDEEXCLUDE mimic standard desktop applications. These programs quietly add malicious directory paths to Windows Defender exclusions.
Infection Chain Architecture
The infection chain advances through several stages to establish permanent access. Initial scripts execute PowerShell commands that download second-stage components into local application folders. Operators establish persistence by adding registry values under standard Windows autorun keys.
The core implant is an executable written in Python and compiled using PyInstaller. It creates a local mutex to prevent duplicate running instances on the machine. As the FBI FLASH report noted, “The malware excluded directories for defense evasion and executed PowerShell, achieving persistence for the second stage persistent implant via the Windows registry.”
Next, the payload extracts an internal configuration file to configure remote communications. It decrypts a text file named rantom.txt at runtime to obtain custom functional code. Additionally, the implant can perform DLL side-loading. It copies a trusted Windows system executable into a temporary folder to execute malicious libraries.
Command-and-Control and Exfiltration Behavior
The backdoor relies heavily on the Telegram Bot API to manage infected computers. In their technical breakdown, Group-IB stated, “Samples rely on a network of Telegram bots, users and groups for exfiltration and command-and-control.” The operators deploy both single-bot and dual-bot configurations to coordinate actions.
The primary bot receives instructions and transmits initial connection beacons. A secondary bot frequently handles stage polling and event logging. Moreover, many operator groups display portraits of women and use Persian female names as titles. As Group-IB observed, “Identified Telegram infrastructure remained presented on Telegram as of 2026, rather than being deleted, although some accounts have since been taken over by unrelated actors.”
The implant parses incoming Telegram messages using dedicated text prefixes. A specific prefix allows operators to execute arbitrary system shell commands directly on the host. Another prefix controls backdoor functions like capturing desktop screenshots and collecting running processes. Crucially, the backdoor steals session files from the Telegram Desktop application to hijack user accounts.
Threat Actor Attribution Analysis
Analysts classify the attribution to Handala Hack as suspected with moderate confidence. Research links Handala Hack to an established state actor. Group-IB noted, “Handala is assessed to be an online persona of Void Manticore also tracked as Storm-0842, Banished Kitten, and Red Sandstorm a destructive-and-leak actor assessed to operate on behalf of MOIS.”
Furthermore, official government filings support this operational connection. On March 19, 2026, the Justice Department announced the seizure of four domains tied to Iranian operations. An accompanying affidavit linked the HEAVYGRAM malware directly to Handala Hack intrusion sets. In July 2025, London-based broadcaster Iran International confirmed that hackers leaked staff information after earlier account intrusions.
Defense and Detection Guidance
Organizations must adopt strict endpoint policies to protect against this espionage campaign. Security teams should monitor PowerShell activity for commands that add Windows Defender path exclusions. In addition, administrators must restrict the execution of unverified scripts from user download folders.
Network defenders should inspect traffic for unusual connections to the Telegram Bot API. Blocking unauthorized messaging bots at web gateways prevents attackers from receiving victim beacons. Security teams should also monitor file modifications within the local Telegram Desktop data folders. According to the Group-IB threat intelligence report on HEAVYGRAM, tracking infrastructure clusters helps identify active intrusion attempts. Finally, organizations must enforce multi-factor authentication on all corporate communication accounts.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!