HEAVYGRAM Python backdoor spawning shell via Telegram C2
This rule detects potentially malicious activity where a Python-based process or a PyInstaller-compiled executable invokes a command shell (cmd.exe, powershell.exe) or command execution via 'os.popen', followed by a network connection to 'api.telegram.org' within a 60-second window. This behavior is often characteristic of malware or tools using Telegram's API as a command-and-control (C2) channel or for data exfiltration.
Splunk (SPL)

