logo

New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

ID: 45166a06-ff46-504d-9da8-17dcb52f573c

STIX ID: report--45166a06-ff46-504d-9da8-17dcb52f573c

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: [email protected] (The Hacker News)

...
...

ThreatFabric observed a new TrickMo Android banking trojan variant (Jan–Feb 2026) targeting banking and cryptocurrency users in France, Italy, and Austria; the variant uses a runtime-loaded dex.module and an embedded local TON proxy for C2, and adds SSH tunnelling, SOCKS5 proxying, and network reconnaissance commands that turn infected devices into programmable network pivots. Distribution is via dropper apps impersonating TikTok and fake Google Play Services, with sample package names provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.