HEAVYGRAM: FBI warns of malware used in Iranian cyber operations

18 Sep 2026

FBI released a technical security advisory on September 15, 2026, about a malware named HEAVYGRAM that has been used by Iranian cyber actors since 2023.

 

Through this blog, we will understand what the HEAVYGRAM malware is about, how threat actors are using it, the threat it poses, and what organizations can do to defend against it.

About the vulnerabilities

Campaign name 

Threat type 

Malware families & Targeted Platform 

Target 

Command & Control  

Attack Vector 

Iranian  

Cyber  

campaign 

Windows backdoor/Surveillance malware 

HEAVYGRAM & Microsoft Windows 

  • Dissidents 
  • Journalists 
  • Activists 
  • Other individuals of interest 

Telegram-based C2 

Social engineering via messaging apps like Telegram (hence the name HEAVYGRAM), followed by delivery of a malicious file disguised as legit software or a document. 

 

The malware, which is particularly delivered through files disguised as legit apps or documents, can help threat actors establish persistence, collect system information, capture screenshot/audio, steal credentials, and communicate with the attacker-controlled infrastructure through Telegram.

The threat posed by the vulnerability

HEAVYGRAM may allow attackers to:

 

  • Execute commands and deploy additional payloads.
  • Establish persistence on Windows systems.
  • Steal browser credentials and sensitive information.
  • Capture screenshots and microphone audio.
  • Collect messaging and email-related data.
  • Exfiltrate information through Telegram-based C2.

SharkStriker’s recommendations

 

  • Ensure Windows EDR/antivirus protection is enabled and updated.
  • Block execution of untrusted files received through email and messaging applications.
  • Search EDR/SIEM telemetry using the HEAVYGRAM IOCs published by the FBI.
  • If infection is suspected, isolate the endpoint immediately and investigate potential credential compromise.
  • Reset compromised credentials and invalidate affected sessions after containment.

SharkStriker’s actions

 

  • SOC Team recommends conducting an IOC-based search across monitored Windows endpoints.
  • Review EDR, SIEM, DNS, proxy, and network telemetry for HEAVYGRAM indicators.
  • Investigate any endpoint matching the published IOCs.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE