778fcc6a38d4667d762c1c34…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Bot RAT (provisional). Telegram Bot RAT (provisional) is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key “UTF-8”). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional. Indicators: https://api.telegram.org/bot8737455264:AAGg3F8FKuk-HTClr_xX-lGdMkNQ3VJemP0/.

Recovered configuration

package
com.zrox.carrier
telegram_bot_token
8737455264:AAGg3F8FKuk-HTClr_xX-lGdMkNQ3VJemP0
telegram_chat_id
7687499928

Identification

SHA-256
778fcc6a38d4667d762c1c346990580a65137d581392729ce5e04826958753b0
MD5
34a4622ceec9f5a4e4b4a600224a3136

Observed

Families
Telegram Bot RAT (provisional)
First seen
2026-08-30

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.telegram.org/bot8737455264:AAGg3F8FKuk-HTClr_xX-lGdMkNQ3VJemP0/ domain - https Telegram Bot RAT (provisional) 2026-08-30

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Bot RAT (provisional)

**Telegram Bot RAT (provisional)** is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot<token>/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key "UTF-8"). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional.