security
May 3, 2026
By Teun
Telegram Mini Apps abused for crypto scams and Android malware delivery
A large-scale fraud operation called FEMITBOT uses Telegram's Mini App feature to run crypto scams, impersonate brands like Apple, NVIDIA and Disney, and distribute Android malware - all within Telegram's built-in browser.
Telegram’s Mini Apps feature is being used in a large fraud campaign that mixes crypto scams, brand impersonation, and Android malware delivery inside the Telegram app itself, according to BleepingComputer’s report on the operation known as FEMITBOT. The scheme takes advantage of Telegram’s built-in browser, which can make phishing pages feel like part of the app rather than an external website.
Mini Apps are lightweight web apps that run inside Telegram’s WebView, the embedded browser component that lets a page open without leaving the chat interface. That convenience is useful for legitimate services, but it also gives attackers a place to present fake login pages, fake rewards, and fake product offers with less friction than a normal browser redirect.
According to the report, FEMITBOT has been observed using that setup to impersonate major brands including Apple, NVIDIA, and Disney. The goal is not just brand theft for its own sake, but to create a believable front for investment fraud, giveaway scams, and other schemes that pressure users into handing over credentials, wallet access, or payment details.
The operation is described as large-scale, which suggests a repeatable infrastructure rather than a one-off phishing page. That matters because Telegram bots and Mini Apps can be spun up quickly, distributed through chat links, and replaced when one domain or bot gets flagged. For attackers, Telegram is attractive because it combines messaging, automation, and web content in a single environment.
The Android side of the campaign raises the stakes further. Instead of stopping at credential theft or crypto scam pages, the operators also use the same ecosystem to deliver Android malware, according to the report. In practice, that usually means luring a user into downloading an APK, the Android application package format used to install apps outside Google Play.
Sideloaded APKs are a common route for mobile malware because they bypass the normal app-store review and warning flow. Once installed, a malicious app can be used for a range of follow-on activity, including stealing messages, tracking the device, or displaying more fraudulent prompts that keep the scam going.
The use of Telegram’s Mini Apps is notable because it blurs the line between a chat app and a web delivery platform. A user may think they are just interacting with a bot, but the bot can launch a page that behaves like a normal service, complete with buttons, forms, and brand styling. That makes it easier to create a convincing false sense of legitimacy.
Scams like this also benefit from Telegram’s scale and its automation features. Bots can send messages, collect responses, and route victims into different flows depending on what they click, which is the same basic pattern used by many phishing kits elsewhere on the web. The difference here is that the whole sequence stays inside Telegram long enough to reduce suspicion.
BleepingComputer says FEMITBOT is using this combination of social engineering and app delivery to spread crypto fraud and Android payloads through Telegram’s own interface. The campaign is another example of how attackers adapt legitimate platform features into a delivery layer for scams and mobile malware.