• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    HEAVYGRAM Python backdoor spawning shell via Telegram C2

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•1•0•4

    This rule detects potentially malicious activity where a Python-based process or a PyInstaller-compiled executable invokes a command shell (cmd.exe, powershell.exe) or command execution via 'os.popen', followed by a network connection to 'api.telegram.org' within a 60-second window. This behavior is often characteristic of malware or tools using Telegram's API as a command-and-control (C2) channel or for data exfiltration.

    Splunk (SPL)

    Tags

    T1059 - Command and Scripting InterpreterT1059.001 - PowerShellT1059.003 - Windows Command ShellT1071.001 - Web ProtocolsT1041 - Exfiltration Over C2 ChannelTA0002 - ExecutionTA0010 - ExfiltrationProcess CreationCommand ExecutionNetwork Connection OutboundData ExfiltrationWindowsCrowdstrike Falcon EDRSentinelone EDRCybereason EDRCarbonblack EDRspl

    Found in

    • HEAVYGRAM Telegram Backdoor Used by Handala HackLast updated 21 days ago
    • HEAVYGRAM Telegram Backdoor Used by Handala HackLast updated 21 days ago
    • HEAVYGRAM Telegram Backdoor Used by Handala HackLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?