The FBI assesses that cyber actors linked to Iran’s Ministry of Intelligence and Security (MOIS) have used the modular Windows malware framework HEAVYGRAM since fall 2023 against Iranian dissidents, anti-government journalists, opposition groups, and other individuals Tehran considers threats worldwide. The operators use Telegram, WhatsApp, and Instagram social-engineering lures, impersonating IT-service providers to persuade targets to install AnyDesk or trojanized applications posing as Pictory Premium, Telegram Authenticator, and KeePass.
HEAVYGRAM uses Telegram Bot API infrastructure for command-and-control and data exfiltration, while Vultr S3 storage supports payload and data staging. Its implants can conduct host reconnaissance, execute commands, capture screenshots, steal browser credentials and sessions, collect Telegram and WhatsApp data and Outlook and Gmail content, and access removable media; optional modules enable screen and audio recording. Organizations supporting at-risk Iranian communities should scrutinize suspicious remote-access deployments and look for Telegram-based C2 activity, credential theft, and counterfeit software installers.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
FBI assesses that Iranian Ministry of Intelligence and Security cyber actors began using HEAVYGRAM against Iranian dissidents, anti-government journalists, opposition organizations, and other perceived threats worldwide. The actors used social engineering on Telegram, WhatsApp, and Instagram to induce targets to install AnyDesk or trojanized software.
The FBI released an updated FLASH containing technical analysis and additional indicators for HEAVYGRAM, assessing that MOIS actors use the malware for intelligence collection, data leaks, and reputational harm on behalf of Iran.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.