HEAVYGRAM: FBI warns of malware used in Iranian cyber operations
18 Sep 2026
FBI released a technical security advisory on September 15, 2026, about a malware named HEAVYGRAM that has been used by Iranian cyber actors since 2023.
Through this blog, we will understand what the HEAVYGRAM malware is about, how threat actors are using it, the threat it poses, and what organizations can do to defend against it.
About the vulnerabilities
|
Campaign name |
Threat type |
Malware families & Targeted Platform |
Target |
Command & Control |
Attack Vector |
|
Iranian Cyber campaign |
Windows backdoor/Surveillance malware |
HEAVYGRAM & Microsoft Windows |
|
Telegram-based C2 |
Social engineering via messaging apps like Telegram (hence the name HEAVYGRAM), followed by delivery of a malicious file disguised as legit software or a document. |
The malware, which is particularly delivered through files disguised as legit apps or documents, can help threat actors establish persistence, collect system information, capture screenshot/audio, steal credentials, and communicate with the attacker-controlled infrastructure through Telegram.
The threat posed by the vulnerability
HEAVYGRAM may allow attackers to:
- Execute commands and deploy additional payloads.
- Establish persistence on Windows systems.
- Steal browser credentials and sensitive information.
- Capture screenshots and microphone audio.
- Collect messaging and email-related data.
- Exfiltrate information through Telegram-based C2.
SharkStriker’s recommendations
- Ensure Windows EDR/antivirus protection is enabled and updated.
- Block execution of untrusted files received through email and messaging applications.
- Search EDR/SIEM telemetry using the HEAVYGRAM IOCs published by the FBI.
- If infection is suspected, isolate the endpoint immediately and investigate potential credential compromise.
- Reset compromised credentials and invalidate affected sessions after containment.
SharkStriker’s actions
- SOC Team recommends conducting an IOC-based search across monitored Windows endpoints.
- Review EDR, SIEM, DNS, proxy, and network telemetry for HEAVYGRAM indicators.
- Investigate any endpoint matching the published IOCs.