logo

Telegram Mini Apps abused for crypto scams, Android malware delivery

ID: a64d5643-2d26-52b1-91ae-6537cb7500ba

STIX ID: report--a64d5643-2d26-52b1-91ae-6537cb7500ba

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-03

Date Updated: 2026-05-03

Author: Lawrence Abrams

...
...

CTM360 researchers documented FEMITBOT, an abuse of Telegram Mini Apps and bots to run large-scale crypto and brand-impersonation scams that display phishing pages inside Telegram, present fake dashboards to victims, and prompt Android APK sideloading; the operation uses a shared backend across campaigns, tracking pixels for conversion measurement, and distributes malware hosted on domains that validate TLS to avoid browser warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.