Skip to main content
AVOID.NET

FEMITBOT Telegram Mini App Fraud Network

avoid.net/femitbot-telegram-mini-app-fraud-network→0/100·88% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Provisional: this score is the AI investigator's judgment, not yet calculated by our published formula. Treat it as indicative. How scoring works →

anchored·2kjeTP…ctKc
last updated 2026-05-28

Summary

FEMITBOT is a large-scale, centralized fraud-as-a-service network discovered by CTM360 in April 2026 that abuses Telegram Mini Apps to operate fake cryptocurrency platforms, impersonate over 30 global brands, and distribute Android malware across more than 60 domains and 146 active bots. The network harvests Telegram initData authentication tokens to silently access victim sessions, operates in 22+ languages, and uses real-time ad-tech conversion tracking from Meta and TikTok to optimize victim recruitment at global scale. No law enforcement action or attribution to specific threat actors has been publicly confirmed as of May 2026.

Connected Entities

4 entities · 59 linked investigations
Organizations
□Bitget□Binance□Meta Platforms□FEMITBOT Telegram Mini App Fraud Network
Relationships
  • FEMITBOT Telegram Mini App Fraud Network→mentioned with→Meta Platforms(80%)
  • FEMITBOT Telegram Mini App Fraud Network→mentioned with→Bitget(60%)
  • FEMITBOT Telegram Mini App Fraud Network→mentioned with→Binance(60%)
Have evidence about FEMITBOT Telegram Mini App Fraud Network?

Timeline(3 events)

April 2026

CTM360 identifies and documents the FEMITBOT network, discovering the shared API fingerprint 'Welcome to join the FEMITBOT platform' across all attacker domains. Exact date within April not publicly specified.

CTM360 FEMITBOT Report

4 May 2026

BleepingComputer, CyberSecurityNews, Hackread, TechBriefly, and multiple security outlets publish coverage of the FEMITBOT network based on the CTM360 report, bringing the threat to wider public attention.

BleepingComputer

4 May 2026

CTM360 formally publishes the FEMITBOT threat report, detailing 146+ bots, 60+ domains, 30+ impersonated brands, and the initData JWT session hijacking vector.

CTM360
Provenance & Audit Trail

Decision Log

  • #1publishRecorded on Solana ✓5/28/2026, 4:29:26 PM
    slot 422756766 · hash 59pm9s4mF7nna3hqAVwzCVMz1dBgdCz5mKZGCk2ZzU4D

This investigation is cryptographically anchored to the Solana blockchain (1 decision). 8 of 9 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/28/2026, 4:29:08 PM

last updated: 5/28/2026, 4:29:08 PM

6 views

avoid.net — verified advice for a post-truth world