logo

Android banking Trojan TrickMo evolves using TON network for C2

ID: a60d34ba-a447-5f6d-af41-ce1ac57c14d5

STIX ID: report--a60d34ba-a447-5f6d-af41-ce1ac57c14d5

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Pierluigi Paganini

...
...

ThreatFabric researchers identified an evolved TrickMo Android banking trojan (discovered Jan–Feb 2026 targeting users in France, Italy and Austria) that migrated its C2 to The Open Network (TON) and embeds a local TON proxy to blend malicious traffic with legitimate blockchain activity. The variant retains classic banking-fraud features (fake UI, SMS interception, remote control) while adding a network-operative subsystem (HTTP probes, DNS lookups, ping/traceroute, TCP probes) and SSH/SOCKS5 tunnelling, enabling infected devices to act as reconnaissance nodes and programmable pivots for criminal infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.