logo

TrickMo’s Stealthy Upgrade: Android Banking Malware is Pivoting to The Open Network

ID: 71e54b50-f303-5e2e-b696-52966feb8c6f

STIX ID: report--71e54b50-f303-5e2e-b696-52966feb8c6f

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

**Executive summary:** A new TrickMo Android banking trojan variant (Variant C) has been identified that replaces traditional internet-based C2 with The Open Network (TON) overlay via an embedded local TON proxy, evading DNS takedowns and network-edge detection; it ships a dynamically loaded module enabling network reconnaissance (curl, ping, dnslookup, traceroute), SSH tunneling/port forwarding, and an authenticated SOCKS5 proxy to route attacker traffic through infected devices, and is actively distributed in social‑engineering campaigns targeting banking and wallet users in France, Italy, and Austria.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.