Telegram Bot Stealer (provisional)

Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s)

About Telegram Bot Stealer (provisional)

Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a “Free TikTok” app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator’s chat. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
api.telegram.org/bot7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE/ domain 7ceb8663fc2c… 2026-10-05