Threat reportMalwareTL-2026-0450
FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery (CTM360, May 2026)
FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand (TL-2026-0450), also tracked as FEMITBOT, is a high-severity malware campaign, first published 2026-05-03. It is attributed to FEMITBOT operators with medium confidence, affects Telegram Telegram Mini Apps (Bot WebView), maps to 23 MITRE ATT&CK techniques (T1005, T1036.005, T1036.013), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1FEMITBOT operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0450
- Threat ID
- TL-2026-0450
- Also known as
- FEMITBOT, FEMITBOT platform
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- FEMITBOT operators
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial services, retail consumers, cryptocurrency investors, media and entertainment audiences, telecommunications customers, AI and cloud-compute prospects
- Target regions
- Global, Latin America, Middle East, Asia-Pacific, Europe, North America
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand
Malware and tooling: FEMITBOT multi-tenant fraud backend (PHaaS)
How FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand works
FEMITBOT is a fraud-as-a-service platform that weaponises Telegram's Mini App feature to host fake crypto-investment dashboards, AI tools, financial-services scams, and streaming sites, while distributing trojanized Android APKs from the same backend. CTM360 attributes the cluster via a shared API banner — "Welcome to join the FEMITBOT platform" — observed across hundreds of phishing fronts impersonating Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave and Claro. The operation combines Telegram bot delivery, in-WebView phishing UIs, paid Meta/TikTok ad amplification, and Android malware sideload chains for credential theft and advance-fee fraud at industrial scale.
FEMITBOT is a multi-tenant fraud platform uncovered by CTM360 and disclosed publicly on 3 May 2026 via BleepingComputer reporting. The campaign abuses Telegram Mini Apps — lightweight web applications that render inside Telegram's WebView when a user clicks a bot's Start button — to host pixel-perfect phishing dashboards that masquerade as cryptocurrency exchanges, AI productivity suites, video-streaming services, and financial-services portals. Because Mini Apps run inside the trusted Telegram client, victims are not warned by the OS browser about insecure content, mixed-content errors, or invalid TLS — the chrome of Telegram lends apparent legitimacy.
Attribution is performed via a shared backend artefact: every Mini App in the cluster, regardless of impersonated brand, returns the literal string "Welcome to join the FEMITBOT platform" from a backend API call when probed. CTM360 used this banner as a pivot to enumerate the platform's footprint and concluded that a single tenant-aware backend powers all observed campaigns, meaning operators can rebrand, re-language, and re-theme an instance in minutes. This is consistent with phishing-as-a-service economics: the FEMITBOT operators sell or rent platform access while sub-affiliates handle traffic acquisition.
The attack chain typically begins with paid social ads (Meta/Facebook and TikTok pixels were observed on landing pages) or direct Telegram bot links seeded into crypto-interest groups. Victims who tap a link are deep-linked into the Telegram client and prompted to start a bot. The bot's Mini App opens immediately, presenting a polished dashboard that displays a fake account balance (often pre-credited with $5–$50 of "welcome bonus"), a countdown timer creating urgency, and tasks such as "verify deposit", "complete referral", or "download our Android app". The deposit path solicits USDT (TRC20 / BEP20), BNB or TRX transfers to attacker-controlled wallets; the referral path harvests Telegram identity data via the Mini App SDK; the APK path serves a trojanized Android package that, once sideloaded, harvests SMS (for OTP interception), contacts, and overlay-captured banking credentials.
Brand impersonation is broad and indiscriminate: confirmed lures include Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave (a-i / GPU-cloud impersonation), and Claro (Latin-American telco). Several lures pair an investment narrative with an AI hook ("earn passive income from NVIDIA H100 cloud rentals", "Coreweave AI mining") to ride the 2025–2026 GPU-compute hype cycle. The Telegram Mini App context also lets the operators bypass app-store review entirely for the Android payloads — APKs are hosted on the same FEMITBOT backend, ensuring TLS validity and avoiding mixed-content browser warnings during sideload.
Defensive implications: this is not a single CVE or a single malware family — it is platform-level abuse of a legitimate Telegram feature combined with social-engineering tradecraft. Network defenders should treat the FEMITBOT API banner as a high-confidence detection string, monitor Android EMM telemetry for sideload events sourced from t.me/* or Telegram-linked WebView referrers, and brand-protection teams should sweep for Mini Apps impersonating their organisation. Telegram itself does not currently expose a public takedown API for Mini Apps, so reporting via @notoscam and abuse@telegram.org is the documented escalation path.
MITRE ATT&CK techniques used in TL-2026-0450
Collection
Defense Evasion
T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1036.013 Masquerading: Impersonate Legitimate Application
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056.004 Input Capture: Credential API Hooking; T1539 Steal Web Session Cookie
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication
Initial Access
T1189 Drive-by Compromise; T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service
Execution
T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing
Resource Development
T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware; T1608.005 Stage Capabilities: Link Target
Impact
Affected products and versions in FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand
- Telegram — Telegram Mini Apps (Bot WebView)
Vulnerable versions: all current - Google — Android (sideloaded APK trojans)
Vulnerable versions: Android 9-15 with sideload enabled - Multiple impersonated brands — Brand identities (no software CVE — impersonation only)
Vulnerable versions: Apple; Coca-Cola; Disney; eBay; IBM; Moon Pay; NVIDIA; YouKu; BBC; CineTV
Remediation for FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand
Patches
- No vendor patch — this is platform abuse, not a CVE. Mitigation is policy and detection, not patching.
Immediate actions
- Block known FEMITBOT phishing domains and any newly-registered domains returning the API banner 'Welcome to join the FEMITBOT platform' at perimeter DNS / secure web gateway.
- Push a mobile EMM policy that disables installation from unknown sources on all managed Android devices.
- Communicate to staff and customers that no legitimate brand engages investors through Telegram Mini Apps — treat any unsolicited Telegram bot soliciting deposits or APK downloads as hostile.
- Report impersonating Telegram bots and Mini Apps to abuse@telegram.org and @notoscam; submit takedowns for paid Meta and TikTok ads driving the campaign.
Workarounds
- Restrict or block the Telegram client on corporate-managed mobile devices where business use does not require it.
- Where Telegram is required, disable Mini App / WebView access via Telegram's privacy settings and via MDM web-content filtering on the WebView referrer.
Longer-term hardening
- Deploy Mobile Threat Defense (MTD) with sideload detection and overlay-attack heuristics.
- Subscribe to a brand-protection feed that monitors Telegram Mini App namespaces for impersonation.
- Add YARA / regex content rules at the egress proxy for the FEMITBOT API banner and known Mini App URL patterns.
- Enrol high-risk staff (finance, treasury, exec assistants) in targeted social-engineering awareness training covering Telegram-borne fraud.
Weaknesses (CWE) in FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand
Timeline of FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand
- CTM360 publishes 'TRAP10 via Mini App Scam' advisory documenting Telegram Mini App Ponzi-style investment scams — the precursor methodology that FEMITBOT operators later industrialise.
- Earliest FEMITBOT-banner phishing fronts observed in CTM360 telemetry, coinciding with the surge in AI / GPU-compute investment narratives.
- Cluster scales to multi-brand impersonation including NVIDIA, Coreweave, Apple, Disney; Meta and TikTok pixels added to landing pages for paid traffic amplification.
- Trojanized Android APKs hosted on the same FEMITBOT backend become a confirmed delivery vector, abusing TLS validity of the parent domain to bypass mixed-content sideload warnings.
- Threadlinqs Intelligence Platform begins tracking FEMITBOT under TL-2026-0450; monitoring underway for new impersonation lures and IOC pivots.
- BleepingComputer publishes coverage of CTM360's FEMITBOT research; 'Welcome to join the FEMITBOT platform' API banner disclosed publicly as a high-confidence cluster identifier.
- As of 2026-05-29, FEMITBOT remains an active fraud-as-a-service operation, newly disclosed by CTM360/BleepingComputer on 2026-05-03 with 60+ live domains, 140+ Telegram bots and 30+ impersonated brands still running. No takedown, seizure, arrests, or Telegram action has been reported; as platform abuse (no CVE, no patch) the technique stays fully viable.
Sources cited for FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand
- Telegram Mini Apps abused for crypto scams, Android malware delivery
- CTM360 — TRAP10 via Mini App Scam (precursor advisory to FEMITBOT)
- CTM360 — Online Anti-Fraud solution overview
- Securelist — Telegram phishing bots and channels: how it works
- Forescout — Revamped Phishing Techniques: Telegram and Front-End Hosting Platforms
- Telegram — Bot Web Apps documentation (legitimate platform reference)
Detection coverage for TL-2026-0450
As of 2026-05-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0450 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.