7ceb8663fc2c099e0c0fb0db…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Bot Stealer (provisional). Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a “Free TikTok” app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator’s chat. Family label provisional. Indicators: https://api.telegram.org/bot7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE/.

Recovered configuration

exfil
Telegram Bot API
lure
Free TikTok (decoy redirect https://tiktok.com)
package
teamblackberry.gallery
telegram_bot_token
7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE
telegram_chat_id
8021113409

Identification

SHA-256
7ceb8663fc2c099e0c0fb0db548a25efe305f77494a033897553ff179e4f8405
MD5
fd5771f2593d2337e967c0e32ad6805b

Observed

Families
Telegram Bot Stealer (provisional)
First seen
2026-10-05

APK metadata

Summary

Type
Android · APK
Package
teamblackberry.gallery
Main activity
teamblackberry.gallery.GalleryEyeMainActivity
Internal version
1
Displayed version
1.0
Min SDK
21
Target SDK
32

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (4)

android.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.READ_EXTERNAL_STORAGEteamblackberry.gallery.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.karumi.dexter.DexterActivity
  • teamblackberry.gallery.GalleryEyeMainActivity

Services (1)

  • teamblackberry.gallery.GalleryEyeUtils.GalleryEyeForegroundService

Receivers (1)

  • androidx.profileinstaller.ProfileInstallReceiver

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters — actions

androidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.telegram.org/bot7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE/ domain — https Telegram Bot Stealer (provisional) 2026-10-05

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Bot Stealer (provisional)

Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a "Free TikTok" app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator's chat. Family label provisional.