ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 9 sources: “US, UK and Dutch Agencies Expose Iranian CHOSEN BRICK (HEAVYGRAM) Spyware; Group-IB Links Campaign to Handala Hack” — merged summary and timeline →

Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware

highMalware exploited in the wildimportance 65
AI summary · glm-5.3-flash

Group-IB links HEAVYGRAM, a Telegram-based Windows surveillance backdoor targeting Iranian dissidents and journalists since 2023, to the Handala Hack group with moderate confidence.

Group-IB identified 29 additional HEAVYGRAM samples, loaders, and payloads and linked the operation to Handala Hack with moderate confidence, expanding on US government disclosures. The backdoor has targeted journalists, Iranian dissidents, and government opponents since fall 2023, including a journalist at a UK-based Farsi-language outlet and a US-based victim. It collects screenshots and audio, steals Telegram Desktop data, executes commands, and persists via Windows registry entries, with associated CRUDEEXCLUDE samples adding security exclusions before delivery.

  • Windows backdoor uses Telegram bot API plus bots, accounts, and groups for command-and-control, 24-hour health beacons, and payload delivery.
  • Victims lured by fake contacts or tech support with files masquerading as Pictory, KeePass, and Telegram applications.
  • Group-IB found 29 additional samples and links the campaign to Handala Hack with moderate confidence.
  • Capabilities include screenshots, audio capture, Telegram Desktop data theft, registry persistence, and DLL side-loading.
  • Defenders should monitor Telegram bot API traffic, autorun registry keys, and binaries launched from user-writable directories.
VendorsTelegram
Threat actorsHandala HackMOIS
OrganizationsGroup-IB
CountriesIran

Indicators of compromiseAll →

TypeIndicatorContext
domainams1.vultrobjects.comntimeSSH_17[.]zip ZIP archive download location URL hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4 Decoy video download location U
domainmicbucket.ams1.vultrobjects.comket/Temp/0412.mp4 Decoy video download location URL hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe Malicious executable download lo
domainppt1.sgp1.vultrobjects.comjgdb/efg_d4[.]zip ZIP archive download location URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4 Decoy video download location URL hxxps:/
domainsgp1.vultrobjects.com2174f6e691d6845ac645b68f1f2538 First-stage file URL hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptx Decoy docume
md50a656287defcbd8a9c47385b805993df9d13e27c8eedc30dd78f237013b239cf23f35d First-stage file MD5 0a656287defcbd8a9c47385b805993df First-stage file SHA-256 3f1313c813e51edf5734d9fb99eb93d6c3
md514698d3a03216daa2cf6f39e4f1c40319817f5066be757f5f09b067a80fed3cfe280f6 First-stage file MD5 14698d3a03216daa2cf6f39e4f1c4031 First-stage file SHA-256 8ad63d4d30cd28391318e26f4e9464f302
md516602375fc2dae1eb54580ab7eda656733371483a789a0c23372c52f2 HEAVYGRAM implant or backdoor MD5 16602375fc2dae1eb54580ab7eda6567 HEAVYGRAM implant or backdoor SHA-256 3befcca381deb6b492aa0
md51d947084fdf25e07ec8bcdaf0cec508ae579a1fa697f66d80103a867cf706f67bba32b First-stage file MD5 1d947084fdf25e07ec8bcdaf0cec508a First-stage file SHA-256 0d74156089292eee308017c8e8a7550739
md51e6b601f733bc40eaa58916986bfc5b9f7ed10dc7707833218468d455d3c5fd CRUDEEXCLUDE executable MD5 1e6b601f733bc40eaa58916986bfc5b9 CRUDEEXCLUDE executable SHA-256 ffceb438127725a6a664aba5021
md526892452f724581530c45287c8b7bc67c31431ff0f5fcaf4ccf5cd9484b2066 CRUDEEXCLUDE executable MD5 26892452f724581530c45287c8b7bc67 CRUDEEXCLUDE executable MD5 B9086413E7B6A0C6A11C25D14C22615
md52965817d063f1e8f9889f9126443d631MD5 481C5B5E69A08C3DF206C59FD8DDC0DC Second-stage file MD5 2965817D063F1E8F9889F9126443D631 Encrypted text artifact MD5 D70EBF20E3D697897BAD5BEBF72EA27
md53e7a2fcef1d038d05b20148c573a6499MD5 D70EBF20E3D697897BAD5BEBF72EA271 Second-stage file MD5 3E7A2FCEF1D038D05B20148C573A6499 Second-stage file SHA-256 65e2dbe5c6b670f663d93fd6560847009
md542215c1fb55d945b4d2a0bb188ca4dcfa17ec6455b6b7ae0f04c5b71b1db0d00c5 RAR archive artifact MD5 42215c1fb55d945b4d2a0bb188ca4dcf RAR archive artifact SHA-256 2640fc95373dd299cc61966c2df5ba
md5481c5b5e69a08c3df206c59fd8ddc0dce file MD5 F8B5554808428291ACC65D1FD2EFE01C DLL utility MD5 481C5B5E69A08C3DF206C59FD8DDC0DC Second-stage file MD5 2965817D063F1E8F9889F9126443D631 Encr
md54dcfa4317f2111109cd41f457541ed2bdb05f56ba88d587683319ce6d HEAVYGRAM implant or backdoor MD5 4dcfa4317f2111109cd41f457541ed2b HEAVYGRAM implant or backdoor SHA-256 ec9d3e32a4e78f8cc9581
md54dd0cbdad60e65fb8cd6999bd9359444ea7071abca429f28bfe629a913513c6d604771f4 Decoy RTF file MD5 4dd0cbdad60e65fb8cd6999bd9359444 Decoy RTF file SHA-256 c4e194747d9a268ff56ac1f0708745cbcc16
md55507a3e71aade582dd226b63b1930c5691928e5163ff791c1b4bc535f4ac92510810a6 First-stage file MD5 5507a3e71aade582dd226b63b1930c56 First-stage file SHA-256 844108a626c15395059efa355a66c8462a
md55f3271ba8840be547b1f3a42ea28ebe0e9e5463c12c0a21a7ab37fb7496ab2c5c40bb4 First-stage file MD5 5f3271ba8840be547b1f3a42ea28ebe0 First-stage file SHA-256 067d93741bcab16810ef15c11941245229
md5602174f6e691d6845ac645b68f1f2538d639542464a647e3816af896fb1320aff64ba5 First-stage file MD5 602174f6e691d6845ac645b68f1f2538 First-stage file URL hxxps://sgp1[.]vultrobjects[.]com/jttr
md566fd60d03613decacc3c42d94dd9aab8292887ea4406fce26773992af0bd7dc34951aa84 Decoy MP4 file MD5 66fd60d03613decacc3c42d94dd9aab8 Decoy MP4 file SHA-256 0aee700463efe5155d816b0f4d44edc9f4b4
md56cae314ddcd821dd2a60dff1fa02460a882d52c67d274e3297694009d13fb96 CRUDEEXCLUDE executable MD5 6cae314ddcd821dd2a60dff1fa02460a CRUDEEXCLUDE executable SHA-256 b0308c91a56209222b178e7099e
md57402f2f9263782a4c469570035843510e MD5 B9086413E7B6A0C6A11C25D14C22615F First-stage file MD5 7402F2F9263782A4C469570035843510 First-stage file MD5 EBDD9595B79B39F53909D862499DBC94 Secon
md57d3cce1f9dbaed585b61e6e903d69b9b176bf53c5acd2dad533eda612b05855 Encrypted text artifact MD5 7d3cce1f9dbaed585b61e6e903d69b9b Encrypted text artifact SHA-256 6ddd145622cde2d2f91dace7e1f
md57e23ffadb664b0e53d821478a249d84c382b0833dcb6ba74db3242022 HEAVYGRAM implant or backdoor MD5 7e23ffadb664b0e53d821478a249d84c HEAVYGRAM implant or backdoor SHA-256 e8b633dcad173eb41ef02
md587f7d0b30f7905d282fb464f5ad6c6cfcbe59473091aa4fbbebba6257aed17985e ZIP archive artifact MD5 87f7d0b30f7905d282fb464f5ad6c6cf ZIP archive artifact SHA-256 2deeeda412c40ad515dca940916a37
md58e9e81d1b252d7fa99579e9cf2e4b4bad9af0c411110905ab4ddf4e4f713101c74d9de First-stage file MD5 8e9e81d1b252d7fa99579e9cf2e4b4ba First-stage file SHA-256 a85ce7dde7f83f116436adbdaa8e782e3a
md594779909cc510194900c3cc17d1194c8ca96f9bca1daff22ef49ea7505d52b40d4 ZIP archive artifact MD5 94779909cc510194900c3cc17d1194c8 ZIP archive artifact SHA-256 4a3b003994112b4dd24ac8b9cc4757
md5970fc0fcf3bc5a933d10e8413536f27f20a6d42096fcadc2d8f6dddd8 HEAVYGRAM implant or backdoor MD5 970fc0fcf3bc5a933d10e8413536f27f HEAVYGRAM implant or backdoor SHA-256 d40d730bcfa4cc7f1ee07
md5a1ca53f09b0c6fe3b3b57b5202192d609f6971ec35431cbb113b6b4bc292ea5db0 ZIP archive artifact MD5 a1ca53f09b0c6fe3b3b57b5202192d60 ZIP archive artifact SHA-256 5380ffda12f97cf4d8e0fe02e0580a
md5a3394ef7ffa7e88b2e7efaee4617fe048a527d938f8538d66bcdebcc9771527 Encrypted text artifact MD5 a3394ef7ffa7e88b2e7efaee4617fe04 Encrypted text artifact SHA-256 cbe9e32393529cd79e19a639a1d
md5b2f6f40570ac9085b5463fdb623560de18ee190ac36cf684c2992f6ddd2dda517b RAR archive artifact MD5 b2f6f40570ac9085b5463fdb623560de RAR archive artifact SHA-256 d2d19c7f2e4a5fdcfb34b26f048077
md5b3c1a3eebefafe1346c6a864b542318290940243f6535f51d43edafac943d493159e14 First-stage file MD5 b3c1a3eebefafe1346c6a864b5423182 First-stage file SHA-256 47fa634b13b8ba35bd5669da3059a0c757
md5b66bd18de204d405500dc079876b7cbf8610c15bea1fba417ab8681a6 HEAVYGRAM implant or backdoor MD5 b66bd18de204d405500dc079876b7cbf HEAVYGRAM implant or backdoor SHA-256 e9d2e4e8fac6420ca3b3a
md5b9086413e7b6a0c6a11c25d14c22615f6892452f724581530c45287c8b7bc67 CRUDEEXCLUDE executable MD5 B9086413E7B6A0C6A11C25D14C22615F First-stage file MD5 7402F2F9263782A4C469570035843510 First
md5be98163e7fea224af382a2251252ce4d1262eaf819edebb93dc883b3082cc64c34 ZIP archive artifact MD5 be98163e7fea224af382a2251252ce4d ZIP archive artifact SHA-256 c9e5cbc98e91aa35a260a1f85d7a56
md5c8aeca21d10f6bbb78e1f2a67d78fcad81a6b35ac5f05fa94775429eb HEAVYGRAM implant or backdoor MD5 c8aeca21d10f6bbb78e1f2a67d78fcad HEAVYGRAM implant or backdoor SHA-256 7477f4f25d1cfc3dfb126
md5ca65cc67247d0702ca34eb7b06873bec92cb2f91f9a34953b875eb018b3ef889d2 ZIP archive artifact MD5 ca65cc67247d0702ca34eb7b06873bec ZIP archive artifact SHA-256 65359388b49ae2a982111ebe8ac837
md5cbe1743e9aebd3e3002b2b005deb332c66546ffea6ef8ab8a639c2151b13f9fd6e ZIP archive artifact MD5 cbe1743e9aebd3e3002b2b005deb332c ZIP archive artifact SHA-256 58fb875fedf57055c3fedf59fdedb9
md5d6756063230136f8c55ae27f1a4b0112df9c14b70d2308b7b12033218e77fe1dc7 ZIP archive artifact MD5 d6756063230136f8c55ae27f1a4b0112 ZIP archive artifact SHA-256 4a3aa8f4f0eb37be9778fbdf0b7dd2
md5d70ebf20e3d697897bad5bebf72ea271965817D063F1E8F9889F9126443D631 Encrypted text artifact MD5 D70EBF20E3D697897BAD5BEBF72EA271 Second-stage file MD5 3E7A2FCEF1D038D05B20148C573A6499 Seco
md5d9418fb432631021a15fb896b365d6088e2128128f234ee2e996489317bfa4720b ZIP archive artifact MD5 d9418fb432631021a15fb896b365d608 ZIP archive artifact SHA-256 138a4c9cd617912c2269fae64b6b12
md5e51ff37fb431767dcdec0b5e6d2a786ae594ed1d133bc115315763002 HEAVYGRAM implant or backdoor MD5 e51ff37fb431767dcdec0b5e6d2a786a HEAVYGRAM implant or backdoor SHA-256 886d04b78017f721ed458
md5ebdd9595b79b39f53909d862499dbc94e MD5 7402F2F9263782A4C469570035843510 First-stage file MD5 EBDD9595B79B39F53909D862499DBC94 Second-stage file MD5 F8B5554808428291ACC65D1FD2EFE01C DLL
md5f8b5554808428291acc65d1fd2efe01cMD5 EBDD9595B79B39F53909D862499DBC94 Second-stage file MD5 F8B5554808428291ACC65D1FD2EFE01C DLL utility MD5 481C5B5E69A08C3DF206C59FD8DDC0DC Second-sta
md5fefaefbf09841cef739d090305edc7a4989af36e3a9e648a00f3000c9 HEAVYGRAM implant or backdoor MD5 fefaefbf09841cef739d090305edc7a4 HEAVYGRAM implant or backdoor SHA-256 bb56792212abe160fff64
sha10190940243f6535f51d43edafac943d493159e14ef6b9d3d75fb31bacd7e2fa1d82d617f26dd First-stage file SHA-1 0190940243f6535f51d43edafac943d493159e14 First-stage file MD5 b3c1a3eebefafe1346c6a864b5423182 First
sha10fe3cf4cabadedb382b0833dcb6ba74db3242022b3cc8f5028d85fbceb7c405 HEAVYGRAM implant or backdoor SHA-1 0fe3cf4cabadedb382b0833dcb6ba74db3242022 HEAVYGRAM implant or backdoor MD5 7e23ffadb664b0e53d821478a
sha1168caccbe59473091aa4fbbebba6257aed17985eb30b8c7ec9677a8d1849ee7d17bc15aa ZIP archive artifact SHA-1 168caccbe59473091aa4fbbebba6257aed17985e ZIP archive artifact MD5 87f7d0b30f7905d282fb464f5ad6c6cf Z
sha1292887ea4406fce26773992af0bd7dc34951aa848e782e3af0f0ce87ec6534ec7b8ea83bb33eed Decoy MP4 file SHA-1 292887ea4406fce26773992af0bd7dc34951aa84 Decoy MP4 file MD5 66fd60d03613decacc3c42d94dd9aab8 Decoy M
sha12b11bccdea89d428610c15bea1fba417ab8681a695e7f8a30029ad125c51b3f HEAVYGRAM implant or backdoor SHA-1 2b11bccdea89d428610c15bea1fba417ab8681a6 HEAVYGRAM implant or backdoor MD5 b66bd18de204d405500dc0798
sha12fa0eb74f8a527d938f8538d66bcdebcc977152719470dc7b24793dd1d3a7addacaae Encrypted text artifact SHA-1 2fa0eb74f8a527d938f8538d66bcdebcc9771527 Encrypted text artifact MD5 a3394ef7ffa7e88b2e7efaee4617fe0
sha133e9e5463c12c0a21a7ab37fb7496ab2c5c40bb43b03acb81af0a4d66feaec285e1205258b35 First-stage file SHA-1 33e9e5463c12c0a21a7ab37fb7496ab2c5c40bb4 First-stage file MD5 5f3271ba8840be547b1f3a42ea28ebe0 First
sha13549f6df9c14b70d2308b7b12033218e77fe1dc722f4d49d3645fa9ad4bdb772829c30bf ZIP archive artifact SHA-1 3549f6df9c14b70d2308b7b12033218e77fe1dc7 ZIP archive artifact MD5 d6756063230136f8c55ae27f1a4b0112 Z
sha143d9af0c411110905ab4ddf4e4f713101c74d9de45cbcc164751dcaa24f1a5a15acbe9c4d998 First-stage file SHA-1 43d9af0c411110905ab4ddf4e4f713101c74d9de First-stage file MD5 8e9e81d1b252d7fa99579e9cf2e4b4ba First
sha144068866546ffea6ef8ab8a639c2151b13f9fd6e013280ee02944d11bb4d1f70ee57aa30 ZIP archive artifact SHA-1 44068866546ffea6ef8ab8a639c2151b13f9fd6e ZIP archive artifact MD5 cbe1743e9aebd3e3002b2b005deb332c Z
sha14a2658c66f3aeabdb05f56ba88d587683319ce6d7a712df20d0f6c19bf3029e HEAVYGRAM implant or backdoor SHA-1 4a2658c66f3aeabdb05f56ba88d587683319ce6d HEAVYGRAM implant or backdoor MD5 4dcfa4317f2111109cd41f457
sha153d41445e176bf53c5acd2dad533eda612b05855192aeacbf2315798c4754a4b74e81 Encrypted text artifact SHA-1 53d41445e176bf53c5acd2dad533eda612b05855 Encrypted text artifact MD5 7d3cce1f9dbaed585b61e6e903d69b9
sha15d3cde9f6971ec35431cbb113b6b4bc292ea5db04debee1ce67d2d0759aff3ec1c720b35 ZIP archive artifact SHA-1 5d3cde9f6971ec35431cbb113b6b4bc292ea5db0 ZIP archive artifact MD5 a1ca53f09b0c6fe3b3b57b5202192d60 Z
sha15dd86e22b882d52c67d274e3297694009d13fb96219ed09ed697b4be4879b7091ec53 CRUDEEXCLUDE executable SHA-1 5dd86e22b882d52c67d274e3297694009d13fb96 CRUDEEXCLUDE executable MD5 6cae314ddcd821dd2a60dff1fa02460
sha15f899031ec31431ff0f5fcaf4ccf5cd9484b20664579156159b361d1f663b4143c4fd CRUDEEXCLUDE executable SHA-1 5f899031ec31431ff0f5fcaf4ccf5cd9484b2066 CRUDEEXCLUDE executable MD5 26892452f724581530c45287c8b7bc6
sha16d9817f5066be757f5f09b067a80fed3cfe280f6313dcfb236a24a11889d6923dd9b42a777d4 First-stage file SHA-1 6d9817f5066be757f5f09b067a80fed3cfe280f6 First-stage file MD5 14698d3a03216daa2cf6f39e4f1c4031 First
sha16dd639542464a647e3816af896fb1320aff64ba5470091a231803b4f449bb00e99ebf76eddb7 First-stage file SHA-1 6dd639542464a647e3816af896fb1320aff64ba5 First-stage file MD5 602174f6e691d6845ac645b68f1f2538 First
sha16fcf829720f425f81a6b35ac5f05fa94775429eb0fc6669fd9d52d690ec1903 HEAVYGRAM implant or backdoor SHA-1 6fcf829720f425f81a6b35ac5f05fa94775429eb HEAVYGRAM implant or backdoor MD5 c8aeca21d10f6bbb78e1f2a67
sha1704119320f7ed10dc7707833218468d455d3c5fd53df7f6c63039a798f2db5eb83afc CRUDEEXCLUDE executable SHA-1 704119320f7ed10dc7707833218468d455d3c5fd CRUDEEXCLUDE executable MD5 1e6b601f733bc40eaa58916986bfc5b
sha17ee579a1fa697f66d80103a867cf706f67bba32b7625bd8c22b3f76447de91b728839136c9c3 First-stage file SHA-1 7ee579a1fa697f66d80103a867cf706f67bba32b First-stage file MD5 1d947084fdf25e07ec8bcdaf0cec508a First
sha187dcba4957396a9e594ed1d133bc115315763002ff379810f7c54b1dbaabc91 HEAVYGRAM implant or backdoor SHA-1 87dcba4957396a9e594ed1d133bc115315763002 HEAVYGRAM implant or backdoor MD5 e51ff37fb431767dcdec0b5e6
sha188816b1262eaf819edebb93dc883b3082cc64c34b0d06a0e473f042fb2d3c144a07484fa ZIP archive artifact SHA-1 88816b1262eaf819edebb93dc883b3082cc64c34 ZIP archive artifact MD5 be98163e7fea224af382a2251252ce4d Z
sha188a8d118ee190ac36cf684c2992f6ddd2dda517b577911c16584a2ff173368f848825de4 RAR archive artifact SHA-1 88a8d118ee190ac36cf684c2992f6ddd2dda517b RAR archive artifact MD5 b2f6f40570ac9085b5463fdb623560de R
sha18c6b6236420c876989af36e3a9e648a00f3000c92c62f25ee05a32cdf102212 HEAVYGRAM implant or backdoor SHA-1 8c6b6236420c876989af36e3a9e648a00f3000c9 HEAVYGRAM implant or backdoor MD5 fefaefbf09841cef739d09030
sha19108466c98df01033371483a789a0c23372c52f2ed2c90e9e9bdf32307c377e HEAVYGRAM implant or backdoor SHA-1 9108466c98df01033371483a789a0c23372c52f2 HEAVYGRAM implant or backdoor MD5 16602375fc2dae1eb54580ab7
sha19391928e5163ff791c1b4bc535f4ac92510810a6d282fc407557da61735d2ae9cfc73ee2aa81 First-stage file SHA-1 9391928e5163ff791c1b4bc535f4ac92510810a6 First-stage file MD5 5507a3e71aade582dd226b63b1930c56 First
sha1ac5939a17ec6455b6b7ae0f04c5b71b1db0d00c5cb7f9d512481a50f21461711438e1c5e RAR archive artifact SHA-1 ac5939a17ec6455b6b7ae0f04c5b71b1db0d00c5 RAR archive artifact MD5 42215c1fb55d945b4d2a0bb188ca4dcf R
sha1af9d13e27c8eedc30dd78f237013b239cf23f35d64f302b0a12675a721967d4f2173ed6cfe8a First-stage file SHA-1 af9d13e27c8eedc30dd78f237013b239cf23f35d First-stage file MD5 0a656287defcbd8a9c47385b805993df First
sha1ba3874ca96f9bca1daff22ef49ea7505d52b40d4fba06082be2bdb0c04241f269f98c773 ZIP archive artifact SHA-1 ba3874ca96f9bca1daff22ef49ea7505d52b40d4 ZIP archive artifact MD5 94779909cc510194900c3cc17d1194c8 Z
sha1ea7071abca429f28bfe629a913513c6d604771f4edb9ebffbf452a0f7f21608abb069cc13effb9 Decoy RTF file SHA-1 ea7071abca429f28bfe629a913513c6d604771f4 Decoy RTF file MD5 4dd0cbdad60e65fb8cd6999bd9359444 Decoy R
sha1ef3f7292cb2f91f9a34953b875eb018b3ef889d22af0c822d8219b35b6038d9d42dcf61d ZIP archive artifact SHA-1 ef3f7292cb2f91f9a34953b875eb018b3ef889d2 ZIP archive artifact MD5 ca65cc67247d0702ca34eb7b06873bec Z
sha1f269488e2128128f234ee2e996489317bfa4720bc3aa6c309e3f0a6a4878291c5b2ec73b ZIP archive artifact SHA-1 f269488e2128128f234ee2e996489317bfa4720b ZIP archive artifact MD5 d9418fb432631021a15fb896b365d608 Z
sha1fec45095576d13a20a6d42096fcadc2d8f6dddd80b71eb6f063147d4dfa1b5f HEAVYGRAM implant or backdoor SHA-1 fec45095576d13a20a6d42096fcadc2d8f6dddd8 HEAVYGRAM implant or backdoor MD5 970fc0fcf3bc5a933d10e8413
sha256067d93741bcab16810ef15c11941245229519470dc7b24793dd1d3a7addacaae5 5f3271ba8840be547b1f3a42ea28ebe0 First-stage file SHA-256 067d93741bcab16810ef15c11941245229519470dc7b24793dd1d3a7addacaae Encrypted text artifact SHA-1 2fa0eb74f8a527d938f8538d66bcd
sha2560aee700463efe5155d816b0f4d44edc9f4b4579156159b361d1f663b4143c4fdMD5 66fd60d03613decacc3c42d94dd9aab8 Decoy MP4 file SHA-256 0aee700463efe5155d816b0f4d44edc9f4b4579156159b361d1f663b4143c4fd CRUDEEXCLUDE executable SHA-1 5f899031ec31431ff0f5fcaf4ccf5
sha2560d74156089292eee308017c8e8a7550739ecb6149ff379810f7c54b1dbaabc915 1d947084fdf25e07ec8bcdaf0cec508a First-stage file SHA-256 0d74156089292eee308017c8e8a7550739ecb6149ff379810f7c54b1dbaabc91 HEAVYGRAM implant or backdoor SHA-1 87dcba4957396a9e594ed1d
sha256138a4c9cd617912c2269fae64b6b12d57e926a36c2c62f25ee05a32cdf102212418fb432631021a15fb896b365d608 ZIP archive artifact SHA-256 138a4c9cd617912c2269fae64b6b12d57e926a36c2c62f25ee05a32cdf102212 HEAVYGRAM implant or backdoor SHA-1 8c6b6236420c876989af36e
sha2562640fc95373dd299cc61966c2df5ba9e013280ee02944d11bb4d1f70ee57aa30215c1fb55d945b4d2a0bb188ca4dcf RAR archive artifact SHA-256 2640fc95373dd299cc61966c2df5ba9e013280ee02944d11bb4d1f70ee57aa30 ZIP archive artifact SHA-1 44068866546ffea6ef8ab8a639c2151b
sha2562deeeda412c40ad515dca940916a376d187219ed09ed697b4be4879b7091ec53f7d0b30f7905d282fb464f5ad6c6cf ZIP archive artifact SHA-256 2deeeda412c40ad515dca940916a376d187219ed09ed697b4be4879b7091ec53 CRUDEEXCLUDE executable SHA-1 5dd86e22b882d52c67d274e329769
sha2563befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81dae1eb54580ab7eda6567 HEAVYGRAM implant or backdoor SHA-256 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 Encrypted text artifact SHA-1 53d41445e176bf53c5acd2dad533e
sha2563f1313c813e51edf5734d9fb99eb93d6c3aa6c309e3f0a6a4878291c5b2ec73b5 0a656287defcbd8a9c47385b805993df First-stage file SHA-256 3f1313c813e51edf5734d9fb99eb93d6c3aa6c309e3f0a6a4878291c5b2ec73b ZIP archive artifact SHA-1 f269488e2128128f234ee2e996489317
sha25647fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de45 b3c1a3eebefafe1346c6a864b5423182 First-stage file SHA-256 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 RAR archive artifact SHA-1 88a8d118ee190ac36cf684c2992f6ddd
sha2564a3aa8f4f0eb37be9778fbdf0b7dd282fc407557da61735d2ae9cfc73ee2aa81756063230136f8c55ae27f1a4b0112 ZIP archive artifact SHA-256 4a3aa8f4f0eb37be9778fbdf0b7dd282fc407557da61735d2ae9cfc73ee2aa81 First-stage file SHA-1 9391928e5163ff791c1b4bc535f4ac925108
sha2564a3b003994112b4dd24ac8b9cc4757f4a12576b57b3cc8f5028d85fbceb7c405779909cc510194900c3cc17d1194c8 ZIP archive artifact SHA-256 4a3b003994112b4dd24ac8b9cc4757f4a12576b57b3cc8f5028d85fbceb7c405 HEAVYGRAM implant or backdoor SHA-1 0fe3cf4cabadedb382b0833
sha2565380ffda12f97cf4d8e0fe02e0580aa1a48b4b6da95e7f8a30029ad125c51b3fca53f09b0c6fe3b3b57b5202192d60 ZIP archive artifact SHA-256 5380ffda12f97cf4d8e0fe02e0580aa1a48b4b6da95e7f8a30029ad125c51b3f HEAVYGRAM implant or backdoor SHA-1 2b11bccdea89d428610c15b
sha25658fb875fedf57055c3fedf59fdedb9ebffbf452a0f7f21608abb069cc13effb9e1743e9aebd3e3002b2b005deb332c ZIP archive artifact SHA-256 58fb875fedf57055c3fedf59fdedb9ebffbf452a0f7f21608abb069cc13effb9 Decoy RTF file SHA-1 ea7071abca429f28bfe629a913513c6d604771
sha25665359388b49ae2a982111ebe8ac837d0f3294ceab7a712df20d0f6c19bf3029e65cc67247d0702ca34eb7b06873bec ZIP archive artifact SHA-256 65359388b49ae2a982111ebe8ac837d0f3294ceab7a712df20d0f6c19bf3029e HEAVYGRAM implant or backdoor SHA-1 4a2658c66f3aeabdb05f56b
sha25665e2dbe5c6b670f663d93fd65608470091a231803b4f449bb00e99ebf76eddb73E7A2FCEF1D038D05B20148C573A6499 Second-stage file SHA-256 65e2dbe5c6b670f663d93fd65608470091a231803b4f449bb00e99ebf76eddb7 First-stage file SHA-1 6dd639542464a647e3816af896fb1320aff6
sha2566ddd145622cde2d2f91dace7e1f7edef22f4d49d3645fa9ad4bdb772829c30bfe1f9dbaed585b61e6e903d69b9b Encrypted text artifact SHA-256 6ddd145622cde2d2f91dace7e1f7edef22f4d49d3645fa9ad4bdb772829c30bf ZIP archive artifact SHA-1 3549f6df9c14b70d2308b7b12033218e
sha2567477f4f25d1cfc3dfb1267e35ab4bcf0b30b8c7ec9677a8d1849ee7d17bc15aaf6bbb78e1f2a67d78fcad HEAVYGRAM implant or backdoor SHA-256 7477f4f25d1cfc3dfb1267e35ab4bcf0b30b8c7ec9677a8d1849ee7d17bc15aa ZIP archive artifact SHA-1 168caccbe59473091aa4fbbebba6257a
sha2568219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dds of compromise (IoCs):- Type Indicator Description SHA-256 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd First-stage file SHA-1 0190940243f6535f51d43edafac943d49315
sha256844108a626c15395059efa355a66c8462af0c822d8219b35b6038d9d42dcf61d5 5507a3e71aade582dd226b63b1930c56 First-stage file SHA-256 844108a626c15395059efa355a66c8462af0c822d8219b35b6038d9d42dcf61d ZIP archive artifact SHA-1 ef3f7292cb2f91f9a34953b875eb018b
sha256886d04b78017f721ed458158e3c31300cb7f9d512481a50f21461711438e1c5e1767dcdec0b5e6d2a786a HEAVYGRAM implant or backdoor SHA-256 886d04b78017f721ed458158e3c31300cb7f9d512481a50f21461711438e1c5e RAR archive artifact SHA-1 ac5939a17ec6455b6b7ae0f04c5b71b1
sha2568ad63d4d30cd28391318e26f4e9464f302b0a12675a721967d4f2173ed6cfe8a5 14698d3a03216daa2cf6f39e4f1c4031 First-stage file SHA-256 8ad63d4d30cd28391318e26f4e9464f302b0a12675a721967d4f2173ed6cfe8a First-stage file SHA-1 af9d13e27c8eedc30dd78f237013b239cf23
sha256a85ce7dde7f83f116436adbdaa8e782e3af0f0ce87ec6534ec7b8ea83bb33eed5 8e9e81d1b252d7fa99579e9cf2e4b4ba First-stage file SHA-256 a85ce7dde7f83f116436adbdaa8e782e3af0f0ce87ec6534ec7b8ea83bb33eed Decoy MP4 file SHA-1 292887ea4406fce26773992af0bd7dc34951aa
sha256b0308c91a56209222b178e7099ee03a7b0d06a0e473f042fb2d3c144a07484fa14ddcd821dd2a60dff1fa02460a CRUDEEXCLUDE executable SHA-256 b0308c91a56209222b178e7099ee03a7b0d06a0e473f042fb2d3c144a07484fa ZIP archive artifact SHA-1 88816b1262eaf819edebb93dc883b308
sha256bb56792212abe160fff643631fb69b2081601e6310fc6669fd9d52d690ec190341cef739d090305edc7a4 HEAVYGRAM implant or backdoor SHA-256 bb56792212abe160fff643631fb69b2081601e6310fc6669fd9d52d690ec1903 HEAVYGRAM implant or backdoor SHA-1 6fcf829720f425f81a6b35a
sha256c4e194747d9a268ff56ac1f0708745cbcc164751dcaa24f1a5a15acbe9c4d998MD5 4dd0cbdad60e65fb8cd6999bd9359444 Decoy RTF file SHA-256 c4e194747d9a268ff56ac1f0708745cbcc164751dcaa24f1a5a15acbe9c4d998 First-stage file SHA-1 43d9af0c411110905ab4ddf4e4f713101c74
sha256c9e5cbc98e91aa35a260a1f85d7a5605dc7aa8d2d0b71eb6f063147d4dfa1b5f98163e7fea224af382a2251252ce4d ZIP archive artifact SHA-256 c9e5cbc98e91aa35a260a1f85d7a5605dc7aa8d2d0b71eb6f063147d4dfa1b5f HEAVYGRAM implant or backdoor SHA-1 fec45095576d13a20a6d420
sha256cbe9e32393529cd79e19a639a1d2da93fba06082be2bdb0c04241f269f98c773ef7ffa7e88b2e7efaee4617fe04 Encrypted text artifact SHA-256 cbe9e32393529cd79e19a639a1d2da93fba06082be2bdb0c04241f269f98c773 ZIP archive artifact SHA-1 ba3874ca96f9bca1daff22ef49ea7505
sha256d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377ef6f40570ac9085b5463fdb623560de RAR archive artifact SHA-256 d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e HEAVYGRAM implant or backdoor SHA-1 9108466c98df01033371483
sha256d40d730bcfa4cc7f1ee070f6ce863b03acb81af0a4d66feaec285e1205258b35c5a933d10e8413536f27f HEAVYGRAM implant or backdoor SHA-256 d40d730bcfa4cc7f1ee070f6ce863b03acb81af0a4d66feaec285e1205258b35 First-stage file SHA-1 33e9e5463c12c0a21a7ab37fb7496ab2c5c4
sha256e8b633dcad173eb41ef02686b46779a4a0e53df7f6c63039a798f2db5eb83afc4b0e53d821478a249d84c HEAVYGRAM implant or backdoor SHA-256 e8b633dcad173eb41ef02686b46779a4a0e53df7f6c63039a798f2db5eb83afc CRUDEEXCLUDE executable SHA-1 704119320f7ed10dc770783321846
sha256e9d2e4e8fac6420ca3b3a3a63a3d313dcfb236a24a11889d6923dd9b42a777d44d405500dc079876b7cbf HEAVYGRAM implant or backdoor SHA-256 e9d2e4e8fac6420ca3b3a3a63a3d313dcfb236a24a11889d6923dd9b42a777d4 First-stage file SHA-1 6d9817f5066be757f5f09b067a80fed3cfe2
sha256ec9d3e32a4e78f8cc9581f5cf030f0594debee1ce67d2d0759aff3ec1c720b35111109cd41f457541ed2b HEAVYGRAM implant or backdoor SHA-256 ec9d3e32a4e78f8cc9581f5cf030f0594debee1ce67d2d0759aff3ec1c720b35 ZIP archive artifact SHA-1 5d3cde9f6971ec35431cbb113b6b4bc2
sha256ffceb438127725a6a664aba5021f7625bd8c22b3f76447de91b728839136c9c301f733bc40eaa58916986bfc5b9 CRUDEEXCLUDE executable SHA-256 ffceb438127725a6a664aba5021f7625bd8c22b3f76447de91b728839136c9c3 First-stage file SHA-1 7ee579a1fa697f66d80103a867cf706f67bb
urlhttps://ams1[.]com/RuntimeSSH_17[.]zip ZIP archive download location URL hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4 Decoy video dow
urlhttps://micbucket[m/micbucket/Temp/0412.mp4 Decoy video download location URL hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe Malicious e
urlhttps://ppt1[/jttrepijgdb/efg_d4[.]zip ZIP archive download location URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4 Decoy video download
urlhttps://sgp1[e MD5 602174f6e691d6845ac645b68f1f2538 First-stage file URL hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.p
Full article1,321 words · extracted from cybersecuritynews.com · click to collapse

HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control.

The malware has been used since fall 2023 against journalists, Iranian dissidents and people whose views oppose Iran’s government.

Victims were approached through messaging apps by people posing as familiar contacts or technical support, then sent files disguised as applications or services.

The campaign also relies on persuasive, context-specific decoys. Researchers at Group-IB identified 29 additional HEAVYGRAM samples, loaders and payloads while tracing this activity.

Their findings expand on U.S. government disclosures and link the operation to Handala Hack with moderate confidence, showing a surveillance effort built around social engineering and long-term access.

The impact reaches beyond a single infected computer. HEAVYGRAM can collect screenshots and audio, capture cached information, steal Telegram desktop data, run commands, add new payloads and delete files.

Group-IB said in a report shared with Cyber Security News (CSN) that the combination creates a risk for sources, private communications and sensitive work held by targeted people.

HEAVYGRAM Surveillance Malware

HEAVYGRAM’s operators use Telegram’s bot API to make an infected Windows machine check in, accept commands and send results back.

One configuration relies on a single bot while another uses two bots for check-ins, logging and delivery of later stages. The model can make malicious traffic look like routine web activity, a problem also seen in Telegram bot malware control campaigns.

After installation, the implant records the computer name and sends an initial beacon. It then sends a health message every 24 hours, letting operators see whether the device remains active.

Commands can start programs, collect system details, take screenshots, run secondary malware and exfiltrate Telegram Desktop files.

The attack begins with a convincing lure. First-stage files have posed as Pictory, KeePass and Telegram-related programs, with names chosen to look legitimate.

Some delivery chains use scripts or HTML applications, while others unpack embedded archives. This use of trusted-looking software mirrors trojanized messaging app installers used in other Windows attacks.

HEAVYGRAM killchain (Source - Group-IB)
HEAVYGRAM killchain (Source – Group-IB)

The implant also uses Windows registry entries to survive restarts. Associated CRUDEEXCLUDE samples may add security-exclusion paths before releasing HEAVYGRAM, giving the attackers another way to reduce the chance of detection.

Targeted Surveillance and Defense

The research connects HEAVYGRAM to a campaign aimed at people of interest to Iran, including a journalist at a UK-based Farsi-language news outlet and a U.S.-based victim described in public records.

The reported Handala link also fits the group’s wider history of coercive activity, including MOIS-linked destructive intrusions that have affected organizations in several countries.

A victim may see a decoy document or video while the malware retrieves a later stage and establishes persistence. Operators can later fetch attachments through Telegram, execute them on the host and use DLL side-loading, where a legitimate program loads a harmful companion file.

People at risk should install software only from official vendor sources and verify unexpected contacts through a separate trusted channel.

Press release announcing the seizure of MOIS-linked domains (Source - Group-IB)
Press release announcing the seizure of MOIS-linked domains (Source – Group-IB)

They should limit messaging-app privacy settings, treat unrequested files cautiously, and apply operating-system and security updates promptly. These steps are especially important when a message appears to come from a colleague or support team.

Organizations should isolate systems that match the indicators, review Windows autorun registry keys and review outbound bot API connections for Telegram backdoor delivery tactics.

Teams should identify unusual native-process launches, system folders with trailing spaces and unauthorized access to messaging data directories.

Application control can block binaries launched from APPDATA, ProgramData and other user-writable locations. Where Telegram is not an approved business tool, monitoring or blocking its API traffic can reduce exposure.

Code-signing checks and staff awareness training add useful layers, while threat teams should feed the indicators below into detection and response workflows.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-2568219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26ddFirst-stage file
SHA-10190940243f6535f51d43edafac943d493159e14First-stage file
MD5b3c1a3eebefafe1346c6a864b5423182First-stage file
SHA-25647fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4RAR archive artifact
SHA-188a8d118ee190ac36cf684c2992f6ddd2dda517bRAR archive artifact
MD5b2f6f40570ac9085b5463fdb623560deRAR archive artifact
SHA-256d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377eHEAVYGRAM implant or backdoor
SHA-19108466c98df01033371483a789a0c23372c52f2HEAVYGRAM implant or backdoor
MD516602375fc2dae1eb54580ab7eda6567HEAVYGRAM implant or backdoor
SHA-2563befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81Encrypted text artifact
SHA-153d41445e176bf53c5acd2dad533eda612b05855Encrypted text artifact
MD57d3cce1f9dbaed585b61e6e903d69b9bEncrypted text artifact
SHA-2566ddd145622cde2d2f91dace7e1f7edef22f4d49d3645fa9ad4bdb772829c30bfZIP archive artifact
SHA-13549f6df9c14b70d2308b7b12033218e77fe1dc7ZIP archive artifact
MD5d6756063230136f8c55ae27f1a4b0112ZIP archive artifact
SHA-2564a3aa8f4f0eb37be9778fbdf0b7dd282fc407557da61735d2ae9cfc73ee2aa81First-stage file
SHA-19391928e5163ff791c1b4bc535f4ac92510810a6First-stage file
MD55507a3e71aade582dd226b63b1930c56First-stage file
SHA-256844108a626c15395059efa355a66c8462af0c822d8219b35b6038d9d42dcf61dZIP archive artifact
SHA-1ef3f7292cb2f91f9a34953b875eb018b3ef889d2ZIP archive artifact
MD5ca65cc67247d0702ca34eb7b06873becZIP archive artifact
SHA-25665359388b49ae2a982111ebe8ac837d0f3294ceab7a712df20d0f6c19bf3029eHEAVYGRAM implant or backdoor
SHA-14a2658c66f3aeabdb05f56ba88d587683319ce6dHEAVYGRAM implant or backdoor
MD54dcfa4317f2111109cd41f457541ed2bHEAVYGRAM implant or backdoor
SHA-256ec9d3e32a4e78f8cc9581f5cf030f0594debee1ce67d2d0759aff3ec1c720b35ZIP archive artifact
SHA-15d3cde9f6971ec35431cbb113b6b4bc292ea5db0ZIP archive artifact
MD5a1ca53f09b0c6fe3b3b57b5202192d60ZIP archive artifact
SHA-2565380ffda12f97cf4d8e0fe02e0580aa1a48b4b6da95e7f8a30029ad125c51b3fHEAVYGRAM implant or backdoor
SHA-12b11bccdea89d428610c15bea1fba417ab8681a6HEAVYGRAM implant or backdoor
MD5b66bd18de204d405500dc079876b7cbfHEAVYGRAM implant or backdoor
SHA-256e9d2e4e8fac6420ca3b3a3a63a3d313dcfb236a24a11889d6923dd9b42a777d4First-stage file
SHA-16d9817f5066be757f5f09b067a80fed3cfe280f6First-stage file
MD514698d3a03216daa2cf6f39e4f1c4031First-stage file
SHA-2568ad63d4d30cd28391318e26f4e9464f302b0a12675a721967d4f2173ed6cfe8aFirst-stage file
SHA-1af9d13e27c8eedc30dd78f237013b239cf23f35dFirst-stage file
MD50a656287defcbd8a9c47385b805993dfFirst-stage file
SHA-2563f1313c813e51edf5734d9fb99eb93d6c3aa6c309e3f0a6a4878291c5b2ec73bZIP archive artifact
SHA-1f269488e2128128f234ee2e996489317bfa4720bZIP archive artifact
MD5d9418fb432631021a15fb896b365d608ZIP archive artifact
SHA-256138a4c9cd617912c2269fae64b6b12d57e926a36c2c62f25ee05a32cdf102212HEAVYGRAM implant or backdoor
SHA-18c6b6236420c876989af36e3a9e648a00f3000c9HEAVYGRAM implant or backdoor
MD5fefaefbf09841cef739d090305edc7a4HEAVYGRAM implant or backdoor
SHA-256bb56792212abe160fff643631fb69b2081601e6310fc6669fd9d52d690ec1903HEAVYGRAM implant or backdoor
SHA-16fcf829720f425f81a6b35ac5f05fa94775429ebHEAVYGRAM implant or backdoor
MD5c8aeca21d10f6bbb78e1f2a67d78fcadHEAVYGRAM implant or backdoor
SHA-2567477f4f25d1cfc3dfb1267e35ab4bcf0b30b8c7ec9677a8d1849ee7d17bc15aaZIP archive artifact
SHA-1168caccbe59473091aa4fbbebba6257aed17985eZIP archive artifact
MD587f7d0b30f7905d282fb464f5ad6c6cfZIP archive artifact
SHA-2562deeeda412c40ad515dca940916a376d187219ed09ed697b4be4879b7091ec53CRUDEEXCLUDE executable
SHA-15dd86e22b882d52c67d274e3297694009d13fb96CRUDEEXCLUDE executable
MD56cae314ddcd821dd2a60dff1fa02460aCRUDEEXCLUDE executable
SHA-256b0308c91a56209222b178e7099ee03a7b0d06a0e473f042fb2d3c144a07484faZIP archive artifact
SHA-188816b1262eaf819edebb93dc883b3082cc64c34ZIP archive artifact
MD5be98163e7fea224af382a2251252ce4dZIP archive artifact
SHA-256c9e5cbc98e91aa35a260a1f85d7a5605dc7aa8d2d0b71eb6f063147d4dfa1b5fHEAVYGRAM implant or backdoor
SHA-1fec45095576d13a20a6d42096fcadc2d8f6dddd8HEAVYGRAM implant or backdoor
MD5970fc0fcf3bc5a933d10e8413536f27fHEAVYGRAM implant or backdoor
SHA-256d40d730bcfa4cc7f1ee070f6ce863b03acb81af0a4d66feaec285e1205258b35First-stage file
SHA-133e9e5463c12c0a21a7ab37fb7496ab2c5c40bb4First-stage file
MD55f3271ba8840be547b1f3a42ea28ebe0First-stage file
SHA-256067d93741bcab16810ef15c11941245229519470dc7b24793dd1d3a7addacaaeEncrypted text artifact
SHA-12fa0eb74f8a527d938f8538d66bcdebcc9771527Encrypted text artifact
MD5a3394ef7ffa7e88b2e7efaee4617fe04Encrypted text artifact
SHA-256cbe9e32393529cd79e19a639a1d2da93fba06082be2bdb0c04241f269f98c773ZIP archive artifact
SHA-1ba3874ca96f9bca1daff22ef49ea7505d52b40d4ZIP archive artifact
MD594779909cc510194900c3cc17d1194c8ZIP archive artifact
SHA-2564a3b003994112b4dd24ac8b9cc4757f4a12576b57b3cc8f5028d85fbceb7c405HEAVYGRAM implant or backdoor
SHA-10fe3cf4cabadedb382b0833dcb6ba74db3242022HEAVYGRAM implant or backdoor
MD57e23ffadb664b0e53d821478a249d84cHEAVYGRAM implant or backdoor
SHA-256e8b633dcad173eb41ef02686b46779a4a0e53df7f6c63039a798f2db5eb83afcCRUDEEXCLUDE executable
SHA-1704119320f7ed10dc7707833218468d455d3c5fdCRUDEEXCLUDE executable
MD51e6b601f733bc40eaa58916986bfc5b9CRUDEEXCLUDE executable
SHA-256ffceb438127725a6a664aba5021f7625bd8c22b3f76447de91b728839136c9c3First-stage file
SHA-17ee579a1fa697f66d80103a867cf706f67bba32bFirst-stage file
MD51d947084fdf25e07ec8bcdaf0cec508aFirst-stage file
SHA-2560d74156089292eee308017c8e8a7550739ecb6149ff379810f7c54b1dbaabc91HEAVYGRAM implant or backdoor
SHA-187dcba4957396a9e594ed1d133bc115315763002HEAVYGRAM implant or backdoor
MD5e51ff37fb431767dcdec0b5e6d2a786aHEAVYGRAM implant or backdoor
SHA-256886d04b78017f721ed458158e3c31300cb7f9d512481a50f21461711438e1c5eRAR archive artifact
SHA-1ac5939a17ec6455b6b7ae0f04c5b71b1db0d00c5RAR archive artifact
MD542215c1fb55d945b4d2a0bb188ca4dcfRAR archive artifact
SHA-2562640fc95373dd299cc61966c2df5ba9e013280ee02944d11bb4d1f70ee57aa30ZIP archive artifact
SHA-144068866546ffea6ef8ab8a639c2151b13f9fd6eZIP archive artifact
MD5cbe1743e9aebd3e3002b2b005deb332cZIP archive artifact
SHA-25658fb875fedf57055c3fedf59fdedb9ebffbf452a0f7f21608abb069cc13effb9Decoy RTF file
SHA-1ea7071abca429f28bfe629a913513c6d604771f4Decoy RTF file
MD54dd0cbdad60e65fb8cd6999bd9359444Decoy RTF file
SHA-256c4e194747d9a268ff56ac1f0708745cbcc164751dcaa24f1a5a15acbe9c4d998First-stage file
SHA-143d9af0c411110905ab4ddf4e4f713101c74d9deFirst-stage file
MD58e9e81d1b252d7fa99579e9cf2e4b4baFirst-stage file
SHA-256a85ce7dde7f83f116436adbdaa8e782e3af0f0ce87ec6534ec7b8ea83bb33eedDecoy MP4 file
SHA-1292887ea4406fce26773992af0bd7dc34951aa84Decoy MP4 file
MD566fd60d03613decacc3c42d94dd9aab8Decoy MP4 file
SHA-2560aee700463efe5155d816b0f4d44edc9f4b4579156159b361d1f663b4143c4fdCRUDEEXCLUDE executable
SHA-15f899031ec31431ff0f5fcaf4ccf5cd9484b2066CRUDEEXCLUDE executable
MD526892452f724581530c45287c8b7bc67CRUDEEXCLUDE executable
MD5B9086413E7B6A0C6A11C25D14C22615FFirst-stage file
MD57402F2F9263782A4C469570035843510First-stage file
MD5EBDD9595B79B39F53909D862499DBC94Second-stage file
MD5F8B5554808428291ACC65D1FD2EFE01CDLL utility
MD5481C5B5E69A08C3DF206C59FD8DDC0DCSecond-stage file
MD52965817D063F1E8F9889F9126443D631Encrypted text artifact
MD5D70EBF20E3D697897BAD5BEBF72EA271Second-stage file
MD53E7A2FCEF1D038D05B20148C573A6499Second-stage file
SHA-25665e2dbe5c6b670f663d93fd65608470091a231803b4f449bb00e99ebf76eddb7First-stage file
SHA-16dd639542464a647e3816af896fb1320aff64ba5First-stage file
MD5602174f6e691d6845ac645b68f1f2538First-stage file
URLhxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptxDecoy document download location
URLhxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/efg_d4[.]zipZIP archive download location
URLhxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4Decoy video download location
URLhxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_def7[.]zipZIP archive download location
URLhxxps://sgp1[.]vultrobjects[.]com/downloads/pictory/Pictory_premium_ver9.0.4.exeMalicious executable download location
URLhxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_17[.]zipZIP archive download location
URLhxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4Decoy video download location
URLhxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exeMalicious executable download location

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/heavygram-surveillance-malware/