The Federal Bureau of Investigation (FBI) released a FBI Liaison Alert System (FLASH) to disseminate a detailed malware analysis of the HEAVYGRAM malware. They assessed that Iranian cyber actors are using HEAVYGRAM malware to conduct malicious cyber activity to target Iranian dissidents, journalists opposed to Iran, and other opposition groups around the world on behalf of the Government of Iran’s Ministry of Intelligence and Security (MOIS). MOIS cyber actors likely use this malware to collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets.
The FBI also assessed MOIS cyber actors have deployed multiple versions of the malware to infect victim systems. The victim profile included Iranian dissidents, journalists opposed to Iran, members of organizations with beliefs counter to Government of Iran narratives, and other individuals Iran perceives as a threat to the Iranian government. Iranian cyber actors have used social engineering to successfully deliver the malware and infect victims. The malware samples analyzed were categorized as masquerading malware (stage 1), persistent implant (stage 2), and related stage 2 malware that contained additional or unique functions.
Seven samples were obtained and analyzed through investigations. The actors used social engineering via social media platforms such as Telegram, WhatsApp, and Instagram to communicate with victims while offering IT services. Upon accepting IT services, victims would either download AnyDesk and potentially provide actors with access strings or victims would download a malware file masquerading as a program installer that the victim used which started a chain of infection. A subset of malware was modular in behavior and relied upon development similarities. The cyber actors have used this malware dating back to the Fall of 2023.
This is an update to the previously published FLASH-20260320-001, entitled “Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets.” This FLASH provides a more detailed malware analysis with additional indicators of compromise (IOCs) previously not included in FLASH-20260320-001. Organizations are urged to use the IOCs and detection signatures in this FLASH to identify HEAVYGRAM malware samples. If identified, follow guidance in the recommended mitigation section.

