LiMP VPN
All news

HEAVYGRAM Steals Telegram Sessions Without Password

HEAVYGRAM Steals Telegram Sessions Without Password

In short: Group-IB researchers identified 29 new samples of HEAVYGRAM, a multi-stage Windows backdoor linked to the Iran-affiliated Handala Hack group. The malware disguises itself as trusted tools (KeePass, Telegram, Pictory) and, once installed, silently steals active Telegram Desktop session files — granting full account access without a password or 2FA prompt. Confirmed victims include journalists and dissidents targeted for opposing the Iranian government.

What is HEAVYGRAM and who is behind it

On September 22, 2026, Group-IB published a detailed technical breakdown of the HEAVYGRAM campaign, identifying 29 previously unknown samples along with associated loaders and payloads. Group-IB assesses with moderate confidence that HEAVYGRAM is linked to Handala Hack — a hacktivist persona believed to operate under the direction of Iran's Ministry of Intelligence (MOIS). US federal authorities have independently corroborated this attribution in court documents.

The earliest confirmed HEAVYGRAM sample dates to September 13, 2023, placing the active campaign at over three years. Iran International confirmed that journalist data was stolen through HEAVYGRAM intrusions in 2024 and 2025. Learn more about encrypted data transmission on the LiMP VPN features page.

How the attack works: infection chain

The attack begins with social engineering. Victims receive an archive or file through a messaging app, disguised as a trusted application — KeePass, Telegram, Pictory, or another recognisable program. Running the first-stage file triggers a PowerShell chain that silently pulls down additional components.

Intermediate stages use WSF/VBS scripts and HTA files. The final payload is a Python script compiled into an executable via PyInstaller, which serves as the core HEAVYGRAM implant. Alongside it, an associated tool called CRUDEEXCLUDE — a Delphi utility — adds the malware's directories to Microsoft Defender exclusion paths, blinding the antivirus to the intrusion.

The core threat: Telegram session theft without a password

HEAVYGRAM's most dangerous capability is the theft of Telegram Desktop session files. Telegram stores active session state in local files on the device. By copying those files, an attacker gains complete access to the victim's Telegram account — no password required, no 2FA challenge, and no notification sent to the victim's phone.

This gives the attacker full visibility into the victim's conversations and the ability to act as the victim within Telegram. Changing the account password after session-file theft does not revoke the stolen session — the attacker retains access until the victim manually terminates it under Telegram settings ("Settings" → "Devices" → "Terminate all other sessions").

The malware's command-and-control (C2) communication runs over the Telegram Bot API, meaning attack traffic blends seamlessly with ordinary Telegram messaging traffic, making detection at the network level extremely difficult.

Full capability set

Beyond session file theft, HEAVYGRAM supports a broad set of espionage functions:

  • Remote command execution on the infected device;
  • Screenshot capture and audio recording;
  • System, network and process enumeration;
  • File and browser data exfiltration;
  • DLL side-loading of additional payloads;
  • Persistence via Windows autorun registry keys.

What this means for your digital privacy

HEAVYGRAM illustrates a core principle: messaging apps are not safe channels for receiving executable files or archives from unknown contacts — even from accounts that appear familiar, since those accounts may themselves be compromised.

Telegram Desktop on a PC warrants extra attention: unlike the mobile app, desktop session files are stored locally and can be stolen by malware. Periodically reviewing active sessions under Telegram "Settings" → "Devices" and terminating any unrecognised entries is essential hygiene.

Encrypting your network traffic — for example with LiMP VPN — makes it harder for attackers to observe your network activity and intercept data on untrusted or public networks. However, the primary defence against HEAVYGRAM is straightforward: never run files received from unknown sources in any messaging app, and keep security software updated. For more on digital privacy, visit the LiMP VPN security blog.

Sources