ProBackend
cyber fraud money laundering
2 hours ago6 min read

Telegram's Mini Apps Are Now a Delivery Surface for Crypto Scams and Android Malware

CTM360 researchers tracked a fraud network they call FEMITBOT that turns Telegram Mini Apps into fake crypto, AI, and streaming sites — then harvests deposits, personal data, and finally pushes Android malware through a "verification" prompt. Here's how the pipeline works, which brands were impersonated, and what to tell your users.

The headline: a fraud ring that lives inside Telegram

Cybersecurity firm CTM360 has published a write-up on a large-scale fraud operation that uses Telegram's Mini Apps feature to host everything from fake crypto exchanges to counterfeit streaming services, then escalates to Android malware once a victim tries to withdraw their "profits." The researchers named the campaign FEMITBOT, after a string found in the platform's API responses, and say it runs on shared infrastructure that operators can re-skin at will — different domains, different bots, different brands, same scam engine underneath.

What makes the operation notable is not the scam logic itself — advance-fee and fake-investment schemes are old — but where it lives. Everything happens inside Telegram, using features people already trust, which is exactly why this campaign deserves a spot in your user-awareness briefings.

What Telegram Mini Apps are, and why they're useful to scammers

Telegram Mini Apps are lightweight web applications that run inside Telegram's built-in browser. Legitimately, they enable services such as payments, account access, and interactive tools without requiring users to leave the messaging app. That "no need to leave the app" property is precisely the attack surface: a phishing page rendered in Telegram's in-app WebView inherits the perceived trust of the messenger itself.

According to the CTM360 report shared with BleepingComputer, FEMITBOT uses Telegram bots and embedded Mini Apps to create convincing, app-like experiences directly within the platform. The user never sees an alarming browser redirect to an unknown site; they see what looks like a feature of Telegram they opted into by pressing "Start."

How the FEMITBOT pipeline works, step by step

The reported flow follows a consistent pattern across campaigns:

  1. The bot as front door. A user interacts with a Telegram bot and clicks "Start." The bot launches a Mini App that displays a phishing page inside Telegram's built-in WebView, making the fraudulent site appear as part of the app itself.
  2. Fake dashboards and manufactured urgency. Once inside, victims are shown dashboards with fake balances or "earnings," often paired with countdown timers or limited-time offers designed to create a sense of urgency and short-circuit deliberate thinking.
  3. The withdrawal trap. When users attempt to withdraw funds, they are prompted to make a deposit or complete referral tasks — the classic structure of investment and advance-fee scams, where the "profit" is only ever reachable by paying more.
  4. Escalation to malware. Some Mini Apps go further and attempt to distribute malware in the form of Android APKs, typically framed as a necessary "verification" or app-install step to access the victim's supposed earnings.

A commodity backend: one platform, many faces

Researchers say the activity uses a shared backend in which multiple phishing domains return the same API response, "Welcome to join the FEMITBOT platform", evidence that seemingly separate campaigns are all riding the same infrastructure. The operation uses Telegram bots to display phishing sites directly within the social platform, and the infrastructure is explicitly designed for reuse across campaigns, allowing attackers to easily switch branding, languages, and themes.

The impersonation list reported by CTM360 reads like a Fortune 500 highlight reel: Apple, Coca-Cola, Disney, eBay, IBM, Moon Pay, NVIDIA, and YouKu, among others. The scam categories are just as broad, fake cryptocurrency platforms, counterfeit financial services, bogus AI tools, and pirated streaming sites, with brand names borrowed purely to borrow credibility and lift engagement.

The operators also run the campaign like a marketing business. The Mini App pages embed tracking scripts, including Meta and TikTok tracking pixels, to track user activity, measure conversions, and, the researchers assess, likely optimize campaign performance. In other words, this is fraud run with the analytics discipline of a legitimate growth team.

The Android payload: small details, big evasion wins

The malware-distribution arm targets Android users with APKs impersonating brands including BBC, NVIDIA, CineTV, Coreweave, and Claro. Users are prompted to download Android APK files, open links within the in-app browser, or install progressive web apps that mimic legitimate software.

CTM360 highlights two deliberate tradecraft choices that make these downloads harder to second-guess:

  • Filename hygiene. "The APK filenames are carefully chosen to resemble legitimate applications or use random-looking names that don't immediately trigger suspicion," the researchers explain.
  • Certificate-correct hosting. "The APKs are hosted on the same domain as the API, ensuring TLS certificate validity and avoiding mixed-content warnings in the browser." By serving the malicious APK from the very HTTPS domain the Mini App already talks to, the download triggers none of the usual browser warnings that might tip off a cautious user.

That second point is the quietly alarming one: the strongest visual signal a non-technical user has, a padlock, no warnings, is engineered to be present at the exact moment they install malware.

Why this lands in the fraud-and-laundering conversation

FEMITBOT sits at the intersection of two trends this blog tracks closely. First, the commoditization of scam infrastructure: a shared, re-skinnable backend with brand templates, multilingual support, and conversion analytics lowers the skill floor for running crypto fraud at scale. Second, the maturation of Android threat delivery outside Google Play, recent campaigns such as the RemControl banking malware and the AI-assisted RatHat malware show the same destination for victims lured off official app stores. A messaging platform's embedded apps and bot ecosystem is simply the next efficient path to the sideload prompt.

What to tell your users

CTM360's guidance, restated practically:

  • Treat every bot-invited "opportunity" as untrusted. Be cautious with Telegram bots that promote crypto investments or prompt you to launch Mini Apps, especially if you're asked to deposit funds or download apps.
  • No legitimate investment pays you to receive your own money. A withdrawal that requires a deposit, a "verification fee," or referral tasks is the scam's real objective, not a hurdle on the way to your profit.
  • Android users: don't sideload. Avoid installing APK files outside Google Play, and treat a request to "verify your account by installing the app" as a red flag by default. Progressive web app installs asked for by a bot deserve the same suspicion.
  • A padlock proves encryption, not legitimacy. As FEMITBOT shows, scammers now maintain valid TLS all the way through their malware delivery.

Bottom line

FEMITBOT is less a novel scam than a distribution upgrade: the same old advance-fee and investment fraud, relocated into a trusted messenger, wrapped in app-like experiences, served from certificate-clean infrastructure, and instrumented with the ad-tech tooling of a real marketing stack. Defenders should treat in-app browsers and mini-app platforms as a phishing surface equal to email, and user awareness content should explicitly cover the "you must deposit/verify to withdraw" pattern, it is the load-bearing wall of the entire scheme.

Source: BleepingComputer, "Telegram Mini Apps abused for crypto scams, Android malware delivery" (Lawrence Abrams), citing CTM360 research.

the headline: a fraud ring that lives inside

More blogs