05cacd5e8417b6f1a1f5bb17…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Bot RAT (provisional). Telegram Bot RAT (provisional) is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key “UTF-8”). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional. Indicators: https://api.telegram.org/bot8737455264:AAFzxyduoJzD6JHvxf1Olwy1LhkoRhAoaSI/.

Recovered configuration

package
com.tech.learner
telegram_bot_token
8737455264:AAFzxyduoJzD6JHvxf1Olwy1LhkoRhAoaSI
telegram_chat_id
7687499928

Identification

SHA-256
05cacd5e8417b6f1a1f5bb17a493a1cc4823e4ce9ede06a43199b097e5a6dc11
MD5
68cca2ba1589f74aa6b0b9824931cf23

Observed

Families
Telegram Bot RAT (provisional)
First seen
2026-09-24

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.telegram.org/bot8737455264:AAFzxyduoJzD6JHvxf1Olwy1LhkoRhAoaSI/ domain - https Telegram Bot RAT (provisional) 2026-09-24

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Bot RAT (provisional)

**Telegram Bot RAT (provisional)** is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot<token>/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key "UTF-8"). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional.