TrickMo Android Banking Malware Targets Banking, Wallet, and Authenticator Apps
ID: 1b88baae-c75a-5c9d-8456-de68046eeaa8
STIX ID: report--1b88baae-c75a-5c9d-8456-de68046eeaa8
Feed Name: cybersecurityNews.com
A new, more stealthy TrickMo Android banking malware variant is actively targeting banking apps, digital wallets, and authenticator applications in Europe (notably France, Italy, and Austria). The variant abuses Android accessibility to achieve full device takeover—recording screens, logging keystrokes, intercepting and suppressing OTPs—injects a runtime dex module for its remote-control engine, and routes C2 through The Open Network (TON) using .adnl endpoints plus on-device SOCKS5/SSH tunnelling and DNS-over-HTTPS to evade detection; the report includes multiple SHA-256 hashes, malicious package names, and mitigation guidance for users and financial institutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
