Expanding the Investigation: Deep Dive into Latest TrickMo Samples
ID: 84deaa55-c6bb-5a56-b10c-24e9cb91e694
STIX ID: report--84deaa55-c6bb-5a56-b10c-24e9cb91e694
Feed Name: Zimperium Blog
Zimperium analyzed a new TrickMo banking-trojan variant that employs sophisticated evasion and credential-theft techniques—OTP interception, screen recording, overlay attacks, accessibility-service abuse, and a novel WebView-based UI that captures device PIN/patterns and Android ID. The report identifies 40 variants (16 droppers, 22 active C2s), exposed C2 data containing ~13,000 unique victim IPs and millions of records across multiple countries, maps MITRE ATT&CK techniques, and provides IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
