The FBI assesses that cyber actors linked to Iran’s Ministry of Intelligence and Security (MOIS) have used the modular Windows malware framework HEAVYGRAM since fall 2023 against Iranian dissidents, anti-government journalists, opposition groups, and other individuals Tehran considers threats worldwide. The operators use Telegram, WhatsApp, and Instagram social-engineering lures, impersonating IT-service providers to persuade targets to install AnyDesk or trojanized applications posing as Pictory Premium, Telegram Authenticator, and KeePass.
HEAVYGRAM uses Telegram Bot API infrastructure for command-and-control and data exfiltration, while Vultr S3 storage supports payload and data staging. Its implants can conduct host reconnaissance, execute commands, capture screenshots, steal browser credentials and sessions, collect Telegram and WhatsApp data and Outlook and Gmail content, and access removable media; optional modules enable screen and audio recording. Organizations supporting at-risk Iranian communities should scrutinize suspicious remote-access deployments and look for Telegram-based C2 activity, credential theft, and counterfeit software installers.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced the seizure of four MOIS-linked domains, including Justicehomeland[.]org, Karmabelow80[.]org, Handala-Redwanted[.]to, and Handala-Hack[.]to. Its affidavit also described HEAVYGRAM intrusions involving a UK-based Farsi-language journalist and a separate U.S.-based victim.
FBI assesses that Iranian Ministry of Intelligence and Security cyber actors began using HEAVYGRAM against Iranian dissidents, anti-government journalists, opposition organizations, and other perceived threats worldwide. The actors used social engineering on Telegram, WhatsApp, and Instagram to induce targets to install AnyDesk or trojanized software.
Gurucul documented HEAVYGRAM lure filenames, Vultrobjects object-storage payload-hosting URLs, and associated MD5, SHA-1, and SHA-256 hashes. The report also detailed the backdoor's Telegram-based command-and-control and exfiltration, screenshot capture, remote command execution, persistence, and DLL sideloading capabilities.
Handala Hack was assessed to be operated by Void Manticore, also known as Banished Kitten, Red Sandstorm, and Storm-0842, an actor affiliated with Iran's Ministry of Intelligence and Security. The assessment links this persona to the HEAVYGRAM backdoor and CRUDEEXCLUDE defense-evasion utility.
Group-IB assessed with moderate confidence that the HEAVYGRAM surveillance operation is linked to Handala Hack and identified 29 additional HEAVYGRAM-related samples, loaders, and payloads. The investigation also associated CRUDEEXCLUDE with the campaign, noting that it may create security-exclusion paths before HEAVYGRAM deployment.
The FBI released an updated FLASH containing technical analysis and additional indicators for HEAVYGRAM, assessing that MOIS actors use the malware for intelligence collection, data leaks, and reputational harm on behalf of Iran.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 135 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcethehackernews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcegroup-ib.com
Open sourcefbi.gov
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.