67765a467b7feb4ec8e8d116…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Bot RAT (provisional). Telegram Bot RAT (provisional) is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key “UTF-8”). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional. Indicators: https://api.telegram.org/bot8737455264:AAFzxyduoJzD6JHvxf1Olwy1LhkoRhAoaSI/.

Recovered configuration

package
com.android.googleaccountmanager
telegram_bot_token
8737455264:AAFzxyduoJzD6JHvxf1Olwy1LhkoRhAoaSI
telegram_chat_id
7687499928

Identification

SHA-256
67765a467b7feb4ec8e8d116b576f93cc7953693a293e842541bffa043c79613
MD5
2ca660b8a6762d02bbc4929c0f18377b

Observed

Families
Telegram Bot RAT (provisional)
First seen
2026-10-03

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.telegram.org/bot8737455264:AAFzxyduoJzD6JHvxf1Olwy1LhkoRhAoaSI/ domain - https Telegram Bot RAT (provisional) 2026-10-03

Signing certificate

Subject CN
AG
Issuer CN
AG
Fingerprint
4f7023b9e7b418932c825d255fb80b4d96279b897f5dd35c799e6c600150d474

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Bot RAT (provisional)

**Telegram Bot RAT (provisional)** is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot<token>/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key "UTF-8"). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional.