TrickMo Banking Trojan Resurgence: New Features
ID: 7ac9c15e-5568-53d8-9f85-d8950425397f
STIX ID: report--7ac9c15e-5568-53d8-9f85-d8950425397f
Feed Name: Cyble Blog
This report analyzes the TrickMo Android banking trojan, tracing its emergence in 2019 and a resurgence in 2023 with new capabilities: JsonPacker-based obfuscation, overlay HTML injection to capture credentials, expanded command set (45+ commands), Accessibility-service abuse for auto-clicking and log collection, module download capability, and exfiltration to a tracked C2 (http://keepass.ltd, 194.169.175.138). It enumerates targeted banking, crypto, and messaging apps, provides sample hashes and IOCs, and maps observed behaviors to MITRE ATT&CK techniques while offering defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
