FEMITBOT Telegram Mini App Fraud Network
Provisional: this score is the AI investigator's judgment, not yet calculated by our published formula. Treat it as indicative. How scoring works →
anchored·2kjeTP…ctKcSummary
FEMITBOT is a large-scale, centralized fraud-as-a-service network discovered by CTM360 in April 2026 that abuses Telegram Mini Apps to operate fake cryptocurrency platforms, impersonate over 30 global brands, and distribute Android malware across more than 60 domains and 146 active bots. The network harvests Telegram initData authentication tokens to silently access victim sessions, operates in 22+ languages, and uses real-time ad-tech conversion tracking from Meta and TikTok to optimize victim recruitment at global scale. No law enforcement action or attribution to specific threat actors has been publicly confirmed as of May 2026.
Connected Entities
4 entities · 59 linked investigations- FEMITBOT Telegram Mini App Fraud Network→mentioned with→Meta Platforms(80%)
- FEMITBOT Telegram Mini App Fraud Network→mentioned with→Bitget(60%)
- FEMITBOT Telegram Mini App Fraud Network→mentioned with→Binance(60%)
Connected Through
3 shared actors · 536 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Binanceorganization
- □Bitgetorganization
- □Meta Platformsorganization
Timeline(3 events)
April 2026
CTM360 identifies and documents the FEMITBOT network, discovering the shared API fingerprint 'Welcome to join the FEMITBOT platform' across all attacker domains. Exact date within April not publicly specified.
CTM360 FEMITBOT Report4 May 2026
BleepingComputer, CyberSecurityNews, Hackread, TechBriefly, and multiple security outlets publish coverage of the FEMITBOT network based on the CTM360 report, bringing the threat to wider public attention.
BleepingComputer4 May 2026
CTM360 formally publishes the FEMITBOT threat report, detailing 146+ bots, 60+ domains, 30+ impersonated brands, and the initData JWT session hijacking vector.
CTM360Decision Log
- slot 422756766 · hash 59pm9s4mF7nna3hqAVwzCVMz1dBgdCz5mKZGCk2ZzU4D
This investigation is cryptographically anchored to the Solana blockchain (1 decision). 8 of 9 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/28/2026, 4:29:08 PM
last updated: 5/28/2026, 4:29:08 PM
6 viewsavoid.net — verified advice for a post-truth world