Telegram Bot Stealer (provisional)
Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s) · Active 2026-10-05 → 2026-10-08 (experimental)
About Telegram Bot Stealer (provisional)
Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a “Free TikTok” app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator’s chat. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| api.telegram.org/bot7940561257:AAE7CIwiSx_z_fkzjBuE4hQ13qoPg2gD5JE/ | domain | 7ceb8663fc2c… | 2026-10-05 |
| api.telegram.org/bot8783284554:AAFGqSI5cPBErEGRa2BkRZ6LH4E7m6VSRVQ/ | domain | 9ea98d083024… | 2026-10-08 |