logo

TrickMo Variant Routes Android Trojan Traffic Through TON

ID: 75c5e10d-2f94-5e5b-a4a9-0ac642fcdc4b

STIX ID: report--75c5e10d-2f94-5e5b-a4a9-0ac642fcdc4b

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

ThreatFabric identified a new TrickMo Android banking trojan variant (TrickMo C) active in Jan–Feb 2026 against users in France, Italy and Austria; the variant embeds a native TON proxy to route C2 via The Open Network (TON) blockchain, making traditional domain takedowns ineffective. It retains device-takeover capabilities (accessibility abuse, WebView overlays, keylogging, screen streaming, OTP suppression) and adds programmable network pivoting (curl, dnslookup, ping, telnet, traceroute) plus an SSH client and on-device SOCKS5 proxy to route attacker traffic through victims' IPs, increasing fraud and reconnaissance potential.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.