A Program Sent in a Chat Is Not Installed: Lessons From HEAVYGRAM

Most intrusions do not begin with a technical vulnerability. They begin with a message: someone who looks familiar, or who says they are "technical support", sends a file and asks you to install it. The case below is a well documented example of that method.
In short, as of 18 September 2026: HEAVYGRAM is Windows spyware in use since autumn 2023. It reached its victims through messaging apps, disguised as well-known programs, and received its commands over Telegram. The rule that stops it is simple: never install a program from a file you received in a chat, whoever appears to have sent it.
What was published
On 17 September 2026, the security firm Group-IB published an analysis of 29 previously undocumented samples of HEAVYGRAM and of a related family, CRUDEEXCLUDE. It builds on US government disclosures from March 2026: the Department of Justice announced a seizure of related domains on 19 March, and the FBI issued a FLASH alert on the malware on 20 March.
Group-IB attributes the malware, with moderate confidence, to Handala Hack, an Iran-linked actor. The publicly described targets were journalists, Iranian dissidents and people critical of the Iranian government. We cover it here for the method, not the target: the same method is used every day by ordinary fraudsters against ordinary businesses.
How the lure works
- ✓The contact. The victim was approached on a messaging app by someone posing as a person they knew, or as technical support.
- ✓The file. They received a program with a believable name: KeePass.exe, like the well-known password manager; Telegram_authenticator.exe, presented as coming from the "Telegram technical team"; WhatssApp.exe, with one extra letter; or a "premium" version of an AI video-editing tool. Some even copied the look of the real program.
- ✓Hiding. Some variants added their own folders to the Windows Defender exclusion list, so they would no longer be scanned, and set themselves to start with Windows.
- ✓Control. The implant checked in and took orders through a Telegram bot. It could run commands, take screenshots, send files out and download further programs.
The last point is why it is hard to spot. To the network, the traffic looks like an ordinary connection to Telegram, a service used by hundreds of millions of people.
The rules that stop it
Group-IB's recommendations for individuals, in plain terms:
- ✓Install software only from the vendor's official source, or through whoever manages your company's computers. Never from a file received on WhatsApp, Telegram, Messenger or email.
- ✓Verify on another channel. If a colleague or "support" sends you a program, call them on the number you already have, not the one in the message.
- ✓Real support does not send programs in a chat. Telegram, WhatsApp and Microsoft will not message you asking you to install an "authenticator".
- ✓Watch for almost-right names. A doubled letter, as in "WhatssApp", is a clear warning sign.
- ✓Keep your operating system up to date.
What your IT provider can check
From the technical recommendations in the same report, the simplest ones to ask for:
- ✓review the Windows autorun registry keys (
HKCU\Software\Microsoft\Windows\CurrentVersion\Runand the HKLM equivalent) for unknown entries; - ✓search for a fake
C:\Windows \folder, with a trailing space in the name; - ✓review the antivirus exclusion list: an exclusion nobody in the company added is an alarm;
- ✓where Telegram is not a business tool, monitor or block traffic to api.telegram.org;
- ✓restrict running programs from folders any user can write to, such as %APPDATA% and C:\ProgramData.
If someone has already installed one
Disconnect the computer from the network. Do not reinstall it and do not delete anything until whoever handles security has looked at it, because the traces on it show what happened. From a different device, change the passwords of every account used on that computer.
What we cannot tell you
We cannot tell you whether a particular computer is infected. We do not manage anyone's computers and we do not run security audits. This article summarises what the source says, so you know which rules to apply and what to ask. For your own machines, the answer comes from whoever administers them.
Sources
Group-IB, "HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack", 17 September 2026, which cites the US Department of Justice announcement of 19 March 2026 and the FBI FLASH report of 20 March 2026. Read on 18 September 2026. If you find a difference from the source, write to us and we will correct the article.
📚 Related Resources
Get the 45-Point Acquisition Diligence Checklist
The complete pre-close checklist search funds, independent sponsors, and micro-PE buyers use to verify a business before they sign, free, and yours in one click.
Get the free checklist →