Update on Iranian Cyber Actors' Malware Deployment
Update on Iranian Cyber Actors’ Malware Deployment
The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate a detailed malware analysis of the HEAVYGRAM malware. The FBI assesses that Iranian cyber actors are using HEAVYGRAM malware to conduct malicious cyber activity targeting Iranian dissidents, journalists opposed to Iran, and other opposition groups worldwide on behalf of the Government of Iran’s Ministry of Intelligence and Security (MOIS). MOIS cyber actors likely use this malware to collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets.
Key Findings
- The victim profile includes Iranian dissidents, journalists opposed to Iran, and members of organizations with beliefs counter to Government of Iran narratives.
- Iranian cyber actors have successfully used social engineering to deliver the malware via social media platforms such as Telegram, WhatsApp, and Instagram.
- Victims were tricked into downloading malware files masquerading as legitimate program installers, leading to a chain of infection.
The FBI analyzed seven samples obtained through investigations. This is an update to previously published FLASH-20260320-001, entitled “Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets.” This document provides a more detailed malware analysis with additional IOCs previously not included in FLASH-20260320-001.
A specific malware sample, Pictory_premium_ver9.0.4.exe, masqueraded as an AI video generator. The FBI urges organizations to use the IOCs and detection signatures in this FLASH to identify HEAVYGRAM malware samples. If identified, follow guidance in the Recommended Mitigation section.
For further details, please refer to the complete article: Read full article
🚀 Stay informed and protect your systems!