HeavyGram Turns Telegram into a Remote Control Backdoor

Security researchers have uncovered a sophisticated Windows-based surveillance malware called HeavyGram, which uses Telegram as its communications hub. Rather than relying on dedicated command-and-control servers, attackers leverage Telegram bots, accounts, and groups to issue commands, extract exfiltrated data, and remotely manage compromised machines. HeavyGram has been targeting journalists, Iranian dissidents, and critics of Iran’s government since fall 2023.

The campaign begins with social engineering: victims receive messages via apps from people posing as trusted contacts or technical support, accompanied by files masquerading as legitimate applications or services. Once one of these malicious files is opened—often disguised under familiar names like Pictory, KeePass, or Telegram-related tools—the malware begins its payload chain via scripts, HTML applications, or embedded archives.

How HeavyGram Works

Upon installation, HeavyGram immediately gathers system metadata—computer names, for example—and sends what’s called a “beacon” signal. It then sends a daily “health” check to confirm the device is online and operational. From there, it supports a wide range of spying and data theft functions: screenshot and audio capture, extraction of cached information, stealing Telegram Desktop data, remote command execution, deploying secondary malware, and even deleting files.

To maintain persistence, the malware plants entries in the Windows registry so it runs at startup. Some variants include a component dubbed CRUDEEXCLUDE, which modifies security settings and exclusion lists to avoid detection by antivirus software.

Targets and Ties to Handala Group

The surveillance effort has disproportionately affected individuals critical of Iran’s regime—journalists at a UK-based Farsi-language outlet, for example, and U.S.-based dissidents have been targeted. Investigators see links between HeavyGram and the Handala group, which has prior ties to the Iranian Ministry of Intelligence and Security (MOIS), although those links are assessed with moderate confidence.

The campaign frequently deploys decoy documents, videos, or software to distract victims while more dangerous secondary stages are installed. Attackers also use DLL side-loading, where a legitimate program loads a malicious companion file, letting malicious operations blend in with expected processes.

Advice for Defense

Protecting against HeavyGram requires vigilance. Users should only install software from official vendor sources, verify any unsolicited files or contacts through separate trusted channels, apply operating system and security updates promptly, and tighten messaging-app privacy settings.

Organizations and IT security teams should monitor IoCs (Indicators of Compromise) tied to HeavyGram, inspect Windows autorun registry keys, review any app traffic using the Telegram bot API, and flag suspicious launches from locations like APPDATA or ProgramData. Locking down application control and limiting binary execution from user-writable folders will help reduce risk.

Below are some known file hashes and URLs tied to HeavyGram, including first-stage payloads, archive artifacts, and decoy content, which can assist in detection efforts.

HeavyGram underscores a growing trend: threat actors reaching beyond traditional C2 infrastructures and blending their operations into everyday tools like messaging platforms. For those relying on desktop Telegram or associated apps, it’s a sharp reminder that familiarity doesn’t equate to safety. As surveillance tools evolve, defenders must treat every install, every link, and every system call as potential intrusion vectors.