logo

TrickMo Android Banking Malware Targets Banking, Wallet, and Authenticator Apps

ID: 1b88baae-c75a-5c9d-8456-de68046eeaa8

STIX ID: report--1b88baae-c75a-5c9d-8456-de68046eeaa8

Feed Name: cybersecurityNews.com

Threat Score
83/100

Date Published: 2026-05-12

Date Updated: 2026-05-14

Author: Tushar Subhra Dutta

...
...

A new, more stealthy TrickMo Android banking malware variant is actively targeting banking apps, digital wallets, and authenticator applications in Europe (notably France, Italy, and Austria). The variant abuses Android accessibility to achieve full device takeover—recording screens, logging keystrokes, intercepting and suppressing OTPs—injects a runtime dex module for its remote-control engine, and routes C2 through The Open Network (TON) using .adnl endpoints plus on-device SOCKS5/SSH tunnelling and DNS-over-HTTPS to evade detection; the report includes multiple SHA-256 hashes, malicious package names, and mitigation guidance for users and financial institutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.