ZeroHour
Product

HEAVYGRAM

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware

Group-IB links HEAVYGRAM, a Telegram-based Windows surveillance backdoor targeting Iranian dissidents and journalists since 2023, to the Handala Hack group with moderate confidence.

Group-IB identified 29 additional HEAVYGRAM samples, loaders, and payloads and linked the operation to Handala Hack with moderate confidence, expanding on US government disclosures. The backdoor has targeted journalists, Iranian dissidents, and government opponents since fall 2023, including a journalist at a UK-based Farsi-language outlet and a US-based victim. It collects screenshots and audio, steals Telegram Desktop data, executes commands, and persists via Windows registry entries, with associated CRUDEEXCLUDE samples adding security exclusions before delivery.

Cyber Security Newsupdated · 2h agofirst · 3h agoMalware in the wild 9 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.