Telegram Bot Stealer (provisional)

Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s) · Active 2026-10-05 → 2026-10-08 (experimental)

About Telegram Bot Stealer (provisional)

Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a “Free TikTok” app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator’s chat. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
api.telegram.org/bot7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE/ domain 7ceb8663fc2c… 2026-10-05
api.telegram.org/bot8783284554:AAFGqSI5cPBErEGRa2BkRZ6LH4E7m6VSRVQ/ domain 9ea98d083024… 2026-10-08