Mark RadarMARK RADAR
About
EN
Sign in

Telegram Scam Network FEMITBOT Abuses Mini Apps to Impersonate Crypto and AI Services

1 reports · First detected 2026-05-06 · Last active 2026-05-06

Telegram Mini Apps can provide login, payment and interactive functions within the messaging platform. FEMITBOT exploits users’ trust in remaining inside Telegram by impersonating brands including Binance, OKX and Nvidia. Its scams use fake investment returns, demands for deposits before withdrawals and sideloaded Android apps, combining crypto-asset fraud, brand impersonation and malware distribution in a single framework.

CTM360 disclosed in early May 2026 that FEMITBOT had more than 60 active domains, at least 146 Telegram bots, more than 15 visual templates and more than 100 tracking codes, while impersonating over 30 brands. Some pages demanded an initial deposit or offered malicious APK files. As of May 6, CTM360 had not disclosed the number of victims or the amount of losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)