FEMITBOT Network Exploits Telegram Mini Apps to Spread Crypto Scams and Android Malware
ID: f5e629e2-7b41-51d4-bb22-000ea9ee9e64
STIX ID: report--f5e629e2-7b41-51d4-bb22-000ea9ee9e64
Feed Name: GBHackers
FEMITBOT is a modular, large-scale fraud and malware operation that leverages Telegram Mini Apps and the in-app WebView to present convincing phishing sites, harvest Telegram initData to silently authenticate users via JWT cookies, and push victims to deposit funds or sideload malicious Android APKs. The ecosystem includes dozens of domains, over a hundred Telegram bots, ad-tech tracking for conversion optimization, and feature flags that enable APK distribution—representing a sophisticated performance-marketing style criminal campaign targeting crypto, streaming, AI, and financial service customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
