www.ctm360.com Telegram Mini Apps Exploited for Widespread Crypto Scams and Malware Distribution
Article Content
- •FEMITBOT exploits Telegram Mini Apps for crypto scams and malware distribution.
- •Threat actors impersonate major brands to enhance credibility and lure victims.
- •The operation uses a shared backend for multiple phishing domains and campaigns.
Cybersecurity researchers have identified a large-scale fraud operation utilizing Telegram's Mini App feature, named FEMITBOT. This platform enables threat actors to run various scams, including fake cryptocurrency platforms and financial services, while impersonating well-known brands like Apple and Coca-Cola. The operation employs Telegram bots to display phishing sites within the app, creating a seamless experience for users. Victims are often shown fake dashboards with misleading balances and are pressured to make deposits to withdraw funds. Additionally, some Mini Apps attempt to distribute Android malware disguised as legitimate applications. The infrastructure allows for rapid deployment and campaign optimization, indicating a sophisticated approach to fraud. Users are advised to exercise caution when interacting with Telegram bots promoting crypto investments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Femitbot and Apple in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…