HEAVYGRAM/CHOSEN BRICK Mass File Deletion Following Telegram Bot C2 Activity (Destructive Wipe)

Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.