FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery (CTM360, May 2026) — Threadlinqs Intelligence
As of 2026-05-30, FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery (CTM360, May 2026) is a high-severity malware threat attributed to FEMITBOT operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0450 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: FEMITBOT operators · FINANCIAL
FEMITBOT is a fraud-as-a-service platform that weaponises Telegram's Mini App feature to host fake crypto-investment dashboards, AI tools, financial-services scams, and streaming sites, while
FEMITBOT is a multi-tenant fraud platform uncovered by CTM360 and disclosed publicly on 3 May 2026 via BleepingComputer reporting. The campaign abuses Telegram Mini Apps — lightweight web applications that render inside Telegram's WebView when a user clicks a bot's Start button — to host pixel-perfect phishing dashboards that masquerade as cryptocurrency exchanges, AI productivity suites, video-streaming services, and financial-services portals. Because Mini Apps run inside the trusted Telegram client, victims are not warned by the OS browser about insecure content, mixed-content errors, or invalid TLS — the chrome of Telegram lends apparent legitimacy.
Attribution is performed via a shared backend artefact: every Mini App in the cluster, regardless of impersonated brand, returns the literal string "Welcome to join the FEMITBOT platform" from a backend API call when probed. CTM360 used this banner as a pivot to enumerate the platform's footprint and concluded that a single tenant-aware backend powers all observed campaigns, meaning operators can rebrand, re-language, and re-theme an instance in minutes. This is consistent with phishing-as-a-service economics: the FEMITBOT operators sell or rent platform access while sub-affiliates handle traffic acquisition.
The attack chain typically begins with paid social ads (Meta/Facebook and TikTok pixels were observed on landing pages) or direct Telegram bot links seeded into crypto-interest groups. Victims who tap a link are deep-linked into the Telegram client and prompted to start a bot. The bot's Mini App opens immediately, presenting a polished dashboard that displays a fake account balance (often pre-credited with $5–$50 of "welcome bonus"), a countdown timer creating urgency, and tasks such as "verify deposit", "complete referral", or "download our Android app". The deposit path solicits USDT (TRC20 / BEP20), BNB or TRX transfers to attacker-controlled wallets; the referral path harvests Telegram identity data via the Mini App SDK; the APK path serves a trojanized Android package that, once sideloaded, harvests SMS (for OTP interception), contacts, and overlay-captured banking credentials.
Brand impersonation is broad and indiscriminate: confirmed lures include Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave (a-i / GPU-cloud impersonation), and Claro (Latin-American telco). Several lures pair an investment narrative with an AI hook ("earn passive income from NVIDIA H100 cloud rentals", "Coreweave AI mining") to ride the 2025–2026 GPU-compute hype cycle. The Telegram Mini App context also lets the operators bypass app-store review entirely for the Android payloads — APKs are hosted on the same FEMITBOT backend, ensuring TLS validity and avoiding mixed-content browser warnings during sideload.
Defensive implications: this is not a single CVE or a single malware family — it is platform-level abuse of a legitimate Telegram feature combined with social-engineering tradecraft. Network defenders should treat the FEMITBOT API banner as a high-confidence detection string, monitor Android EMM telemetry for sideload events sourced from t.me/* or Telegram-linked WebView referrers, and brand-protection teams should sweep for Mini Apps impersonating their organisation. Telegram itself does not currently expose a public takedown API for Mini Apps, so reporting via @notoscam and abuse@telegram.org is the documented escalation path.
Weaknesses (CWE)
CWE-1021, CWE-451, CWE-494, CWE-829
Target sectors: financial services, retail consumers, cryptocurrency investors, media and entertainment audiences, telecommunications customers, AI and cloud-compute prospects
Target regions: Global, Latin America, Middle East, Asia-Pacific, Europe, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583.001, T1583.006, T1585.001, T1587.001, T1608.001, T1608.005, T1566, T1566.002, T1566.003