Telegram Scam Network FEMITBOT Abuses Mini Apps to Impersonate Crypto and AI Services
Telegram Mini Apps can provide login, payment and interactive functions within the messaging platform. FEMITBOT exploits users’ trust in remaining inside Telegram by impersonating brands including Binance, OKX and Nvidia. Its scams use fake investment returns, demands for deposits before withdrawals and sideloaded Android apps, combining crypto-asset fraud, brand impersonation and malware distribution in a single framework.
CTM360 disclosed in early May 2026 that FEMITBOT had more than 60 active domains, at least 146 Telegram bots, more than 15 visual templates and more than 100 tracking codes, while impersonating over 30 brands. Some pages demanded an initial deposit or offered malicious APK files. As of May 6, CTM360 had not disclosed the number of victims or the amount of losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →