Technical analysis of the malicious file HEAVYGRAM / Campaign linked to MOIS

How HEAVYGRAM remains active on devices, how it receives commands via Telegram, and what traces it leaves in the system. AKSK publishes the technical analysis of HEAVYGRAM, also known as CHOSEN BRICK, used in cyber espionage campaigns against activists and journalists in various countries. According to the analysis, these activities are linked to cyber actors operating on behalf of Iran's Ministry of Intelligence and Security (MOIS). The document examines the malicious file, execution mechanisms, persistence in the system, communication with command and control (C2) infrastructure, malicious functions, and indicators of compromise. The analysis also includes specific recommendations for identifying, monitoring, and addressing potential compromise cases. Read the full analysis: https://aksk.gov.al/analize-teknike-mbi-skedarin-keqdashes-heavygram-fushate-e-lidhur-me-mois/

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source