logo

FEMITBOT Network Exploits Telegram Mini Apps to Spread Crypto Scams and Android Malware

ID: f5e629e2-7b41-51d4-bb22-000ea9ee9e64

STIX ID: report--f5e629e2-7b41-51d4-bb22-000ea9ee9e64

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Mayura Kathir

...
...

FEMITBOT is a modular, large-scale fraud and malware operation that leverages Telegram Mini Apps and the in-app WebView to present convincing phishing sites, harvest Telegram initData to silently authenticate users via JWT cookies, and push victims to deposit funds or sideload malicious Android APKs. The ecosystem includes dozens of domains, over a hundred Telegram bots, ad-tech tracking for conversion optimization, and feature flags that enable APK distribution—representing a sophisticated performance-marketing style criminal campaign targeting crypto, streaming, AI, and financial service customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.