logo

TrickMo Banking Trojan Resurgence: New Features

ID: 7ac9c15e-5568-53d8-9f85-d8950425397f

STIX ID: report--7ac9c15e-5568-53d8-9f85-d8950425397f

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-07-06

Date Updated: 2026-07-16

...
...

This report analyzes the TrickMo Android banking trojan, tracing its emergence in 2019 and a resurgence in 2023 with new capabilities: JsonPacker-based obfuscation, overlay HTML injection to capture credentials, expanded command set (45+ commands), Accessibility-service abuse for auto-clicking and log collection, module download capability, and exfiltration to a tracked C2 (http://keepass.ltd, 194.169.175.138). It enumerates targeted banking, crypto, and messaging apps, provides sample hashes and IOCs, and maps observed behaviors to MITRE ATT&CK techniques while offering defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.