0a40d131965daedc30852fc7…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Bot RAT (provisional). Telegram Bot RAT (provisional) is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key “UTF-8”). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional. Indicators: https://api.telegram.org/bot8737455264:AAGg3F8FKuk-HTClr_xX-lGdMkNQ3VJemP0/.

Recovered configuration

package
com.zrox.chrome
telegram_bot_token
8737455264:AAGg3F8FKuk-HTClr_xX-lGdMkNQ3VJemP0
telegram_chat_id
7687499928

Identification

SHA-256
0a40d131965daedc30852fc7b158c6c25fef794d45797970f7c4b66d38991eef
MD5
53fcd643cf4a9c5e070d776926ec2852

Observed

Families
Telegram Bot RAT (provisional)
First seen
2026-08-06

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.telegram.org/bot8737455264:AAGg3F8FKuk-HTClr_xX-lGdMkNQ3VJemP0/ domain - https Telegram Bot RAT (provisional) 2026-08-06

Signing certificate

Subject CN
GOOGLE
Issuer CN
GOOGLE
Fingerprint
ccba34be3ca9cb3571dfbbc341945def0620a1d352c1ed1a058b733c17e2071f

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Bot RAT (provisional)

**Telegram Bot RAT (provisional)** is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot<token>/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key "UTF-8"). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional.