Friday, September 11, 2026

FEMITBOT Network Exploits Telegram Mini Apps to Spread Crypto Scams and Android Malware

A large-scale fraud and malware operation called FEMITBOT that abuses Telegram Mini Apps to steal cryptocurrency and infect Android devices.

The campaign shows how trusted in-app web experiences can be turned into powerful tools for social engineering and credential theft.

Telegram Mini Apps are lightweight web applications that run inside Telegram, offering seamless login, payments, and interaction within a familiar interface.

FEMITBOT operators exploit this trust by building convincing fake Mini Apps that load their phishing websites directly inside Telegram’s in-app browser (WebView), making the content appear native and safe to users.

When a victim taps “Launch App” in a Telegram bot, the Mini App loads a phishing site that integrates the official Telegram WebApp SDK via a script from Telegram’s domain.

This allows the attackers’ site to communicate with Telegram and silently receive a data blob called initData, which includes the user’s ID, name, and an authentication hash.

CTM360’s analysis links FEMITBOT to multiple fraud campaigns that impersonate well-known brands across streaming, crypto, AI, and financial services.

Observed lures include fake platforms posing as Netflix, BBC, Youku, Binance, Bitget, OKX, NVIDIA, and various crypto mining pools to create credibility and drive user engagement.

FEMITBOT KIT (Source : CTM360).
FEMITBOT KIT (Source : CTM360).

The ecosystem is modular and template-driven, with at least 15 Mini App “skins,” over 60 active domains, and more than 140 Telegram bots tied to the same backend.

All these components return a recurring message referencing the FEMITBOT platform via a common API response, confirming a shared infrastructure behind seemingly unrelated scams.

FEMITBOT Network Exploits Telegram Mini Apps

The victim flow follows a standard escalation model designed to maximize financial loss. Victims are first lured through Meta ads, Telegram invites, or other social channels, promising passive income, free streaming, cloud mining, or AI compute deals.

After opening the bot and launching the Mini App, the site extracts initData and submits it to an API endpoint that issues a JWT cookie, silently authenticating the user for up to ten days without a password.

The dashboard then displays fake real-time earnings, countdown timers, and limited “VIP slots” to create urgency and push users to make an initial “activation” deposit.

FEMITBOT integrates advanced tracking through Meta (Facebook/Instagram) and TikTok pixels to monitor user activity and optimize conversion funnels.

PageView, Purchase, and rePurchase events are fired on key actions like registration and deposits, giving threat actors detailed insight into which campaigns and lures generate the highest returns.

Analysts observed calls to Meta’s pixel endpoints from the scam pages, confirming the use of mainstream ad-tech infrastructure within this criminal ecosystem.

This level of analytics-driven refinement reflects a mature operation that treats fraud like a performance-marketing pipeline rather than a one-off scam.

Beyond fraud, FEMITBOT’s infrastructure also distributes Android malware through controlled feature flags in the Mini App configuration.

When an appdownloadshowswitch flag is enabled, victims are prompted to install Android APKs that are hosted on the same domains used by the API to maintain TLS validity and avoid browser warnings.

The configuration supports several delivery methods: direct APK download, in-app browser flows, and Progressive Web App prompts that add a malicious shortcut to the home screen without a full install.

APK filenames are crafted to appear legitimate or random-looking, increasing the chance that users will trust and install them on their devices.

FEMITBOT demonstrates how legitimate super-app features like Mini Apps and WebViews can be repurposed for scalable fraud, credential abuse, and mobile malware distribution.

Security teams should monitor for suspicious Telegram bots tied to lookalike domains, unexpected WebApp SDK usage, and brand impersonation involving crypto, streaming, and AI services.

initData Authentication Flow (Source : CTM360).
initData Authentication Flow (Source : CTM360).

Researchers also highlight the need for closer scrutiny of ad-tech signals and pixel activity associated with phishing infrastructure, as these indicators can expose high-volume fraud operations early.

For end users, the core defense remains simple: treat any investment, mining, or high-yield offer inside messaging apps with extreme caution, and avoid sideloading APKs or adding “apps” from untrusted prompts.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News