# FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery (CTM360, May 2026)

> FEMITBOT is a fraud-as-a-service platform that weaponises Telegram's Mini App feature to host fake crypto-investment dashboards, AI tools, financial-services scams, and streaming sites, while distributing trojanized Android APKs from the same backend. CTM360 attributes the cluster via a shared API banner — "Welcome to join the FEMITBOT platform" — observed across hundreds of phishing fronts impersonating Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave and Claro. The operation combines Telegram bot delivery, in-WebView phishing UIs, paid Meta/TikTok ad amplification, and Android malware sideload chains for credential theft and advance-fee fraud at industrial scale.

- **Published:** 2026-05-03T12:00:00Z
- **Last reviewed:** 2026-05-03T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0450
- **ID:** TL-2026-0450
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** FEMITBOT operators
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

FEMITBOT is a multi-tenant fraud platform uncovered by CTM360 and disclosed publicly on 3 May 2026 via BleepingComputer reporting. The campaign abuses Telegram Mini Apps — lightweight web applications that render inside Telegram's WebView when a user clicks a bot's Start button — to host pixel-perfect phishing dashboards that masquerade as cryptocurrency exchanges, AI productivity suites, video-streaming services, and financial-services portals. Because Mini Apps run inside the trusted Telegram client, victims are not warned by the OS browser about insecure content, mixed-content errors, or invalid TLS — the chrome of Telegram lends apparent legitimacy.

Attribution is performed via a shared backend artefact: every Mini App in the cluster, regardless of impersonated brand, returns the literal string "Welcome to join the FEMITBOT platform" from a backend API call when probed. CTM360 used this banner as a pivot to enumerate the platform's footprint and concluded that a single tenant-aware backend powers all observed campaigns, meaning operators can rebrand, re-language, and re-theme an instance in minutes. This is consistent with phishing-as-a-service economics: the FEMITBOT operators sell or rent platform access while sub-affiliates handle traffic acquisition.

The attack chain typically begins with paid social ads (Meta/Facebook and TikTok pixels were observed on landing pages) or direct Telegram bot links seeded into crypto-interest groups. Victims who tap a link are deep-linked into the Telegram client and prompted to start a bot. The bot's Mini App opens immediately, presenting a polished dashboard that displays a fake account balance (often pre-credited with $5–$50 of "welcome bonus"), a countdown timer creating urgency, and tasks such as "verify deposit", "complete referral", or "download our Android app". The deposit path solicits USDT (TRC20 / BEP20), BNB or TRX transfers to attacker-controlled wallets; the referral path harvests Telegram identity data via the Mini App SDK; the APK path serves a trojanized Android package that, once sideloaded, harvests SMS (for OTP interception), contacts, and overlay-captured banking credentials.

Brand impersonation is broad and indiscriminate: confirmed lures include Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, YouKu, BBC, CineTV, Coreweave (a-i / GPU-cloud impersonation), and Claro (Latin-American telco). Several lures pair an investment narrative with an AI hook ("earn passive income from NVIDIA H100 cloud rentals", "Coreweave AI mining") to ride the 2025–2026 GPU-compute hype cycle. The Telegram Mini App context also lets the operators bypass app-store review entirely for the Android payloads — APKs are hosted on the same FEMITBOT backend, ensuring TLS validity and avoiding mixed-content browser warnings during sideload.

Defensive implications: this is not a single CVE or a single malware family — it is platform-level abuse of a legitimate Telegram feature combined with social-engineering tradecraft. Network defenders should treat the FEMITBOT API banner as a high-confidence detection string, monitor Android EMM telemetry for sideload events sourced from t.me/* or Telegram-linked WebView referrers, and brand-protection teams should sweep for Mini Apps impersonating their organisation. Telegram itself does not currently expose a public takedown API for Mini Apps, so reporting via @notoscam and abuse@telegram.org is the documented escalation path.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.001 Acquire Infrastructure: Domains
- T1583.006 Acquire Infrastructure: Web Services
- T1585.001 Establish Accounts: Social Media Accounts
- T1587.001 Develop Capabilities: Malware
- T1608.001 Stage Capabilities: Upload Malware
- T1608.005 Stage Capabilities: Link Target
- T1566 Phishing
- T1566.002 Phishing: Spearphishing Link
- T1566.003 Phishing: Spearphishing via Service
- T1189 Drive-by Compromise
- T1204.001 User Execution: Malicious Link
- T1204.002 User Execution: Malicious File
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1036.013 Masquerading: Impersonate Legitimate Application
- T1553.002 Subvert Trust Controls: Code Signing
- T1056.004 Input Capture: Credential API Hooking
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1102.002 Web Service: Bidirectional Communication
- T1071.001 Application Layer Protocol: Web Protocols
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft

## Sources

- [Telegram Mini Apps abused for crypto scams, Android malware delivery](https://www.bleepingcomputer.com/news/security/telegram-mini-apps-abused-for-crypto-scams-android-malware-delivery/)
- [CTM360 — TRAP10 via Mini App Scam (precursor advisory to FEMITBOT)](https://www.ctm360.com/blogs/trap10-mini-app-scam)
- [CTM360 — Online Anti-Fraud solution overview](https://www.ctm360.com/solutions/online-anti-fraud)
- [Securelist — Telegram phishing bots and channels: how it works](https://securelist.com/telegram-phishing-services/109383/)
- [Forescout — Revamped Phishing Techniques: Telegram and Front-End Hosting Platforms](https://www.forescout.com/blog/revamped-phishing-techniques-how-telegram-and-front-end-hosting-platforms-scale-campaigns/)
- [Telegram — Bot Web Apps documentation (legitimate platform reference)](https://core.telegram.org/bots/webapps)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0450
