TrickMo Android banker adopts TON blockchain for covert comms
ID: f015a73a-b7d4-586e-9806-0913c2086608
STIX ID: report--f015a73a-b7d4-586e-9806-0913c2086608
Feed Name: Bleeping Computer
TrickMo's latest variant ('Trickmo.C') is an Android banking trojan deployed in Europe that hides C2 communications inside The Open Network (TON) using ADNL addresses and an embedded local proxy, making takedowns and attribution more difficult. The modular two-stage malware steals banking and crypto credentials via overlays, keylogging, SMS/OTP interception and live screen streaming, and now supports advanced networking capabilities such as SSH tunneling, remote/local port forwarding and authenticated SOCKS5 proxies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
