Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
Brief
HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control.
The malware has been used since fall 2023 against journalists, Iranian dissidents and people whose views oppose Iran’s government.
Victims were approached through messaging apps by people posing as familiar contacts or technical support, then sent files disguised as applications or services.
The campaign also relies on persuasive, context-specific decoys. Researchers at Group-IB identified 29 additional HEAVYGRAM samples, loaders and payloads while tracing this activity.
Their findings expand on U. S.
