Telegram Bot Stealer (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s)
About Telegram Bot Stealer (provisional)
Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a “Free TikTok” app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator’s chat. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| api.telegram.org/bot7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE/ | domain | 7ceb8663fc2c… | 2026-10-05 |