Threat reportMalwareTL-2026-0450

FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery (CTM360, May 2026)

highACTIVE

FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand (TL-2026-0450), also tracked as FEMITBOT, is a high-severity malware campaign, first published 2026-05-03. It is attributed to FEMITBOT operators with medium confidence, affects Telegram Telegram Mini Apps (Bot WebView), maps to 23 MITRE ATT&CK techniques (T1005, T1036.005, T1036.013), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1FEMITBOT operators
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0450

Threat ID
TL-2026-0450
Also known as
FEMITBOT, FEMITBOT platform
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
FEMITBOT operators
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial services, retail consumers, cryptocurrency investors, media and entertainment audiences, telecommunications customers, AI and cloud-compute prospects
Target regions
Global, Latin America, Middle East, Asia-Pacific, Europe, North America
Detection rules
9
Indicators of compromise
15

Malware and tooling in FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand

Malware and tooling: FEMITBOT multi-tenant fraud backend (PHaaS)

How FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand works

FEMITBOT is a fraud-as-a-service platform that weaponises Telegram's Mini App feature to host fake crypto-investment dashboards, AI tools, financial-services scams, and streaming sites, while distributing trojanized Android APKs from the same backend. CTM360 attributes the cluster via a shared API banner — "Welcome to join the FEMITBOT platform" — observed across hundreds of phishing fronts impersonating Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave and Claro. The operation combines Telegram bot delivery, in-WebView phishing UIs, paid Meta/TikTok ad amplification, and Android malware sideload chains for credential theft and advance-fee fraud at industrial scale.

FEMITBOT is a multi-tenant fraud platform uncovered by CTM360 and disclosed publicly on 3 May 2026 via BleepingComputer reporting. The campaign abuses Telegram Mini Apps — lightweight web applications that render inside Telegram's WebView when a user clicks a bot's Start button — to host pixel-perfect phishing dashboards that masquerade as cryptocurrency exchanges, AI productivity suites, video-streaming services, and financial-services portals. Because Mini Apps run inside the trusted Telegram client, victims are not warned by the OS browser about insecure content, mixed-content errors, or invalid TLS — the chrome of Telegram lends apparent legitimacy.

Attribution is performed via a shared backend artefact: every Mini App in the cluster, regardless of impersonated brand, returns the literal string "Welcome to join the FEMITBOT platform" from a backend API call when probed. CTM360 used this banner as a pivot to enumerate the platform's footprint and concluded that a single tenant-aware backend powers all observed campaigns, meaning operators can rebrand, re-language, and re-theme an instance in minutes. This is consistent with phishing-as-a-service economics: the FEMITBOT operators sell or rent platform access while sub-affiliates handle traffic acquisition.

The attack chain typically begins with paid social ads (Meta/Facebook and TikTok pixels were observed on landing pages) or direct Telegram bot links seeded into crypto-interest groups. Victims who tap a link are deep-linked into the Telegram client and prompted to start a bot. The bot's Mini App opens immediately, presenting a polished dashboard that displays a fake account balance (often pre-credited with $5–$50 of "welcome bonus"), a countdown timer creating urgency, and tasks such as "verify deposit", "complete referral", or "download our Android app". The deposit path solicits USDT (TRC20 / BEP20), BNB or TRX transfers to attacker-controlled wallets; the referral path harvests Telegram identity data via the Mini App SDK; the APK path serves a trojanized Android package that, once sideloaded, harvests SMS (for OTP interception), contacts, and overlay-captured banking credentials.

Brand impersonation is broad and indiscriminate: confirmed lures include Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave (a-i / GPU-cloud impersonation), and Claro (Latin-American telco). Several lures pair an investment narrative with an AI hook ("earn passive income from NVIDIA H100 cloud rentals", "Coreweave AI mining") to ride the 2025–2026 GPU-compute hype cycle. The Telegram Mini App context also lets the operators bypass app-store review entirely for the Android payloads — APKs are hosted on the same FEMITBOT backend, ensuring TLS validity and avoiding mixed-content browser warnings during sideload.

Defensive implications: this is not a single CVE or a single malware family — it is platform-level abuse of a legitimate Telegram feature combined with social-engineering tradecraft. Network defenders should treat the FEMITBOT API banner as a high-confidence detection string, monitor Android EMM telemetry for sideload events sourced from t.me/* or Telegram-linked WebView referrers, and brand-protection teams should sweep for Mini Apps impersonating their organisation. Telegram itself does not currently expose a public takedown API for Mini Apps, so reporting via @notoscam and abuse@telegram.org is the documented escalation path.

MITRE ATT&CK techniques used in TL-2026-0450

Collection

T1005 Data from Local System

Defense Evasion

T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1036.013 Masquerading: Impersonate Legitimate Application

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056.004 Input Capture: Credential API Hooking; T1539 Steal Web Session Cookie

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication

Initial Access

T1189 Drive-by Compromise; T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service

Execution

T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing

Resource Development

T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware; T1608.005 Stage Capabilities: Link Target

Impact

T1657 Financial Theft

Affected products and versions in FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand

  • Telegram — Telegram Mini Apps (Bot WebView)
    Vulnerable versions: all current
  • Google — Android (sideloaded APK trojans)
    Vulnerable versions: Android 9-15 with sideload enabled
  • Multiple impersonated brands — Brand identities (no software CVE — impersonation only)
    Vulnerable versions: Apple; Coca-Cola; Disney; eBay; IBM; Moon Pay; NVIDIA; YouKu; BBC; CineTV

Remediation for FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand

Patches

  • No vendor patch — this is platform abuse, not a CVE. Mitigation is policy and detection, not patching.

Immediate actions

  • Block known FEMITBOT phishing domains and any newly-registered domains returning the API banner 'Welcome to join the FEMITBOT platform' at perimeter DNS / secure web gateway.
  • Push a mobile EMM policy that disables installation from unknown sources on all managed Android devices.
  • Communicate to staff and customers that no legitimate brand engages investors through Telegram Mini Apps — treat any unsolicited Telegram bot soliciting deposits or APK downloads as hostile.
  • Report impersonating Telegram bots and Mini Apps to abuse@telegram.org and @notoscam; submit takedowns for paid Meta and TikTok ads driving the campaign.

Workarounds

  • Restrict or block the Telegram client on corporate-managed mobile devices where business use does not require it.
  • Where Telegram is required, disable Mini App / WebView access via Telegram's privacy settings and via MDM web-content filtering on the WebView referrer.

Longer-term hardening

  • Deploy Mobile Threat Defense (MTD) with sideload detection and overlay-attack heuristics.
  • Subscribe to a brand-protection feed that monitors Telegram Mini App namespaces for impersonation.
  • Add YARA / regex content rules at the egress proxy for the FEMITBOT API banner and known Mini App URL patterns.
  • Enrol high-risk staff (finance, treasury, exec assistants) in targeted social-engineering awareness training covering Telegram-borne fraud.

Weaknesses (CWE) in FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand

CWE-1021, CWE-451, CWE-494, CWE-829

Timeline of FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand

  • CTM360 publishes 'TRAP10 via Mini App Scam' advisory documenting Telegram Mini App Ponzi-style investment scams — the precursor methodology that FEMITBOT operators later industrialise.
  • Earliest FEMITBOT-banner phishing fronts observed in CTM360 telemetry, coinciding with the surge in AI / GPU-compute investment narratives.
  • Cluster scales to multi-brand impersonation including NVIDIA, Coreweave, Apple, Disney; Meta and TikTok pixels added to landing pages for paid traffic amplification.
  • Trojanized Android APKs hosted on the same FEMITBOT backend become a confirmed delivery vector, abusing TLS validity of the parent domain to bypass mixed-content sideload warnings.
  • Threadlinqs Intelligence Platform begins tracking FEMITBOT under TL-2026-0450; monitoring underway for new impersonation lures and IOC pivots.
  • BleepingComputer publishes coverage of CTM360's FEMITBOT research; 'Welcome to join the FEMITBOT platform' API banner disclosed publicly as a high-confidence cluster identifier.
  • As of 2026-05-29, FEMITBOT remains an active fraud-as-a-service operation, newly disclosed by CTM360/BleepingComputer on 2026-05-03 with 60+ live domains, 140+ Telegram bots and 30+ impersonated brands still running. No takedown, seizure, arrests, or Telegram action has been reported; as platform abuse (no CVE, no patch) the technique stays fully viable.

Sources cited for FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand

Detection coverage for TL-2026-0450

As of 2026-05-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0450 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats