FEMITBOT is a large-scale fraud and malware distribution operation that abuses Telegram bots and Mini Apps to run cryptocurrency investment scams and deliver malicious Android software. The operation uses Telegram’s in-app WebView to make fraudulent pages appear native to the platform, increasing user trust and reducing friction during victim interaction. It is characterized by centralized backend infrastructure that supports rapid reuse across many concurrent campaigns, with operators able to swap branding, themes, and languages at scale. FEMITBOT commonly impersonates well-known consumer, technology, media, financial, and cryptocurrency brands to lend credibility to scam offers. Victims are typically lured through social media advertising and unsolicited Telegram invitations, then presented with polished interfaces showing fabricated balances, fake earnings dashboards, countdown timers, expiring offers, and VIP-style upgrade prompts. The workflow pressures victims into depositing funds or recruiting additional users before purported withdrawals are allowed, consistent with organized investment fraud and referral-based scam mechanics. The operation also functions as a malware delivery platform. Some campaigns push malicious Android applications or Progressive Web Apps masquerading as legitimate software, using Telegram-delivered flows and direct download prompts to induce installation. Researchers have linked the activity to a shared kit identified by a recurring backend string associated with the FEMITBOT name, along with a large ecosystem of Telegram bots, impersonated brands, and advertising telemetry used to optimize lure performance. The infrastructure supports multilingual targeting and uses traffic measurement and campaign analytics associated with major advertising platforms, indicating a professionalized and business-like operating model. High-confidence observed behaviors include initial access through social engineering, credential- or session-related abuse via Telegram authentication data, financial theft through fraudulent deposits, malware delivery, and infrastructure concealment measures. FEMITBOT is best understood as an organized cyber-enabled fraud network focused primarily on financial gain rather than espionage or disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a large-scale fraud network abusing Telegram Mini Apps to impersonate cryptocurrency exchanges, streaming services, financial platforms, and AI tools; steals deposits through fake earnings schemes and can also distribute malicious Android APKs.
Centralized fraud infrastructure used to launch and manage hundreds of scam campaigns via Telegram Mini Apps, including cryptocurrency investment scams, phishing-style fake dashboards, and lures to download malicious Android apps/APKs and PWAs.
A large-scale fraud operation abusing Telegram Mini Apps and bots to run crypto and investment scams, impersonate major brands, host phishing pages inside Telegram WebView, and in some cases distribute malicious Android APKs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.