A large-scale fraud and malware operation called FEMITBOT that abuses Telegram Mini Apps to steal cryptocurrency and infect Android devices.
The campaign shows how trusted in-app web experiences can be turned into powerful tools for social engineering and credential theft.
Telegram Mini Apps are lightweight web applications that run inside Telegram, offering seamless login, payments, and interaction within a familiar interface.
FEMITBOT operators exploit this trust by building convincing fake Mini Apps that load their phishing websites directly inside Telegram’s in-app browser (WebView), making the content appear native and safe to users.
When a victim taps “Launch App” in a Telegram bot, the Mini App loads a phishing site that integrates the official Telegram WebApp SDK via a script from Telegram’s domain.
This allows the attackers’ site to communicate with Telegram and silently receive a data blob called initData, which includes the user’s ID, name, and an authentication hash.
CTM360’s analysis links FEMITBOT to multiple fraud campaigns that impersonate well-known brands across streaming, crypto, AI, and financial services.
Observed lures include fake platforms posing as Netflix, BBC, Youku, Binance, Bitget, OKX, NVIDIA, and various crypto mining pools to create credibility and drive user engagement.

The ecosystem is modular and template-driven, with at least 15 Mini App “skins,” over 60 active domains, and more than 140 Telegram bots tied to the same backend.
All these components return a recurring message referencing the FEMITBOT platform via a common API response, confirming a shared infrastructure behind seemingly unrelated scams.
FEMITBOT Network Exploits Telegram Mini Apps
The victim flow follows a standard escalation model designed to maximize financial loss. Victims are first lured through Meta ads, Telegram invites, or other social channels, promising passive income, free streaming, cloud mining, or AI compute deals.
After opening the bot and launching the Mini App, the site extracts initData and submits it to an API endpoint that issues a JWT cookie, silently authenticating the user for up to ten days without a password.
The dashboard then displays fake real-time earnings, countdown timers, and limited “VIP slots” to create urgency and push users to make an initial “activation” deposit.
FEMITBOT integrates advanced tracking through Meta (Facebook/Instagram) and TikTok pixels to monitor user activity and optimize conversion funnels.
PageView, Purchase, and rePurchase events are fired on key actions like registration and deposits, giving threat actors detailed insight into which campaigns and lures generate the highest returns.
Analysts observed calls to Meta’s pixel endpoints from the scam pages, confirming the use of mainstream ad-tech infrastructure within this criminal ecosystem.
This level of analytics-driven refinement reflects a mature operation that treats fraud like a performance-marketing pipeline rather than a one-off scam.
Beyond fraud, FEMITBOT’s infrastructure also distributes Android malware through controlled feature flags in the Mini App configuration.
When an appdownloadshowswitch flag is enabled, victims are prompted to install Android APKs that are hosted on the same domains used by the API to maintain TLS validity and avoid browser warnings.
The configuration supports several delivery methods: direct APK download, in-app browser flows, and Progressive Web App prompts that add a malicious shortcut to the home screen without a full install.
APK filenames are crafted to appear legitimate or random-looking, increasing the chance that users will trust and install them on their devices.
FEMITBOT demonstrates how legitimate super-app features like Mini Apps and WebViews can be repurposed for scalable fraud, credential abuse, and mobile malware distribution.
Security teams should monitor for suspicious Telegram bots tied to lookalike domains, unexpected WebApp SDK usage, and brand impersonation involving crypto, streaming, and AI services.

Researchers also highlight the need for closer scrutiny of ad-tech signals and pixel activity associated with phishing infrastructure, as these indicators can expose high-volume fraud operations early.
For end users, the core defense remains simple: treat any investment, mining, or high-yield offer inside messaging apps with extreme caution, and avoid sideloading APKs or adding “apps” from untrusted prompts.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





