TrickMo Malware Expands Android Attacks On Banking and Crypto Wallet Users
ID: a6057865-d4c6-5c22-8a9e-5e480557540a
STIX ID: report--a6057865-d4c6-5c22-8a9e-5e480557540a
Feed Name: Cyber Press
A new, stealthy TrickMo Android banking trojan variant is actively targeting banking, fintech, and crypto wallet users in France, Italy, and Austria; operators abuse The Open Network (TON) for C2, use Accessibility permission for full device takeover to harvest credentials and OTPs, and convert infected devices into SSH/SOCKS5 proxies to route attacker traffic and bypass IP-based detections. The report includes SHA-256 hashes for the dropper and host applications and notes dormant capabilities for future features (Pine hooking, NFC).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
