Android banking Trojan TrickMo evolves using TON network for C2
ID: a60d34ba-a447-5f6d-af41-ce1ac57c14d5
STIX ID: report--a60d34ba-a447-5f6d-af41-ce1ac57c14d5
Feed Name: Security Affairs
ThreatFabric researchers identified an evolved TrickMo Android banking trojan (discovered Jan–Feb 2026 targeting users in France, Italy and Austria) that migrated its C2 to The Open Network (TON) and embeds a local TON proxy to blend malicious traffic with legitimate blockchain activity. The variant retains classic banking-fraud features (fake UI, SMS interception, remote control) while adding a network-operative subsystem (HTTP probes, DNS lookups, ping/traceroute, TCP probes) and SSH/SOCKS5 tunnelling, enabling infected devices to act as reconnaissance nodes and programmable pivots for criminal infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
