Karam Chatra

Junior CTI Analyst

Blog posts by Karam Chatra

Blog image without title
Malware Analysis
September 17, 2026
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.
Chinese leads data brokers
Threat Intelligence
May 20, 2026
Volume Obfuscation Game: The Lead Data Brokers Out To Waste Your Time
An increasing number of data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. But are they credible?
Ghost Tapped
Threat Intelligence
January 7, 2026
Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware
Group-IB researchers detail the inner workings of Chinese tap-to-pay schemes on Telegram and examine the NFC-enabled Android apps fraudsters are using to steal money from victim’s bank cards and mobile wallets remotely.
Cyber Investigations
June 23, 2025
Middle East Cyber Escalation: From Hacktivism to Sophisticated Threat Operations
Regional Conflict Monitoring (June 13 - 20, 2025)
Scam & Phishing
April 25, 2023
Tech (non)support: Scammers pose as Meta in Facebook account grab ploy
Group-IB Digital Risk Protection discovers more than 3,200 fake Facebook profiles in ongoing phishing campaign that sees scammers impersonate Meta support staff