logo

TrickMo Malware Expands Android Attacks On Banking and Crypto Wallet Users

ID: a6057865-d4c6-5c22-8a9e-5e480557540a

STIX ID: report--a6057865-d4c6-5c22-8a9e-5e480557540a

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Varshini

...
...

A new, stealthy TrickMo Android banking trojan variant is actively targeting banking, fintech, and crypto wallet users in France, Italy, and Austria; operators abuse The Open Network (TON) for C2, use Accessibility permission for full device takeover to harvest credentials and OTPs, and convert infected devices into SSH/SOCKS5 proxies to route attacker traffic and bypass IP-based detections. The report includes SHA-256 hashes for the dropper and host applications and notes dormant capabilities for future features (Pine hooking, NFC).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.