HEAVYGRAM is a multi-functional Windows backdoor/persistent implant attributed to Handala Hack with moderate confidence. It leverages the Telegram bot API for exfiltration and command-and-control, allowing operators to execute commands remotely, exfiltrate data and screenshots, establish persistence and run additional payloads. HEAVYGRAM's infection chain involves tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest.
It operates via a multi-stage infection process, with initial delivery via WSF/VBS scripts, VBS scripts and HTML applications (HTA), executables with embedded archives, or CRUDEEXCLUDE executables with embedded archives. The persistent implant relies on several additional files, including an internal config.py file containing hardcoded configuration strings, and rantom.txt – an encrypted text file with custom function definitions.[/subscribe_to_unlock_form]
HEAVYGRAM is a multi-functional Windows backdoor/persistent implant attributed to Handala Hack with moderate confidence. It leverages the Telegram bot API for exfiltration and command-and-control, allowing operators to execute commands remotely, exfiltrate data and screenshots, establish persistence and run additional payloads. HEAVYGRAM's infection chain involves tailored social engineering, application masquerading, defense evasion and persistent access to compromise targets of interest.
It operates via a multi-stage infection process, with initial delivery via WSF/VBS scripts, VBS scripts and HTML applications (HTA), executables with embedded archives, or CRUDEEXCLUDE executables with embedded archives. The persistent implant relies on several additional files, including an internal config.py file containing hardcoded configuration strings, and rantom.txt – an encrypted text file with custom function definitions.[emaillocker id="1283"]
It handles C2 communication via two functions: send_initial_message and send_health_msg. The malware has been used in operations targeting journalists, dissidents, and other individuals of interest to Iran, further illustrating how tooling associated with the actor can support targeted collection while feeding broader intrusions and hack-and-leak operations.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Exfiltration | E1020 | Automated Exfiltration |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Execution | E1204 | User Execution |
The following reports contain further technical details:
[/emaillocker]