Wire Observer.
Technology

Telegram Hijacked: Malware Turns Messaging App into Remote Control Hub

Telegram Hijacked: Malware Turns Messaging App into Remote Control Hub

A new Windows‑based surveillance backdoor dubbed HEAVYGRAM has been observed leveraging the popular messaging service Telegram as its primary command‑and‑control (C2) infrastructure. Security researchers say the malware replaces traditional server‑based C2 channels with Telegram bots, user accounts and group chats, allowing operators to issue commands, retrieve stolen data and keep infected machines under continuous oversight.

HEAVYGRAM is classified as a remote‑access Trojan that installs itself on compromised Windows hosts and silently records keystrokes, screenshots, and other sensitive information. Once active, the payload establishes a persistent link to Telegram, where it can receive encrypted instructions from the attacker without needing to contact a hard‑coded IP address or domain.

The malware’s architecture exploits Telegram’s public API. After infection, the program creates or hijacks a bot token, joins a pre‑selected group, and begins posting data as messages or files. Operators can then reply within the same chat to trigger actions such as file exfiltration, execution of additional payloads, or alteration of system settings. Because the traffic is routed through Telegram’s legitimate servers, it blends with normal user activity and evades many network‑based detection tools.

Using a mainstream platform for C2 offers several tactical benefits. Telegram’s end‑to‑end encryption, global server distribution, and high availability reduce the risk of takedown. Moreover, the reliance on widely trusted infrastructure complicates attribution, as law‑enforcement agencies must first request data from the service provider, a process that can be delayed or denied under local privacy laws.

Analysts note that HEAVYGRAM’s focus on Windows makes it a potent threat to both enterprise environments and individual users who rely on the operating system’s default security settings. The backdoor’s ability to move data through Telegram means that even networks with strict outbound filtering may inadvertently allow exfiltration, since the traffic appears as ordinary HTTPS traffic to Telegram’s domains.

The technique mirrors a growing trend where threat actors co‑opt legitimate cloud and messaging services—such as Discord, Slack, and Google Drive—as covert C2 channels. These services provide built‑in redundancy and scalability, and their traffic is rarely flagged as malicious by conventional intrusion‑detection systems.

Cybersecurity firms advise organizations to monitor outbound connections to Telegram’s API endpoints, enforce application whitelisting, and apply multi‑factor authentication to any Telegram accounts used for business purposes. Endpoint detection platforms should also be tuned to flag the creation of new bot tokens or the unexpected launch of Telegram client processes on Windows machines.

While the immediate impact of HEAVYGRAM remains under investigation, its emergence underscores the need for continuous threat‑intel sharing and adaptive defensive measures. Researchers expect attackers to refine similar approaches, potentially targeting other popular messaging apps, as they seek ever‑more resilient ways to control compromised devices without exposing a traditional command infrastructure.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related