Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

TrickMo Variant Exploits TON C2 and SOCKS5 to Forge Android Banking Pivots

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-05-12 T 20:19:47 Z | [ 1 MIN READ ]
TrickMo Variant Exploits TON C2 and SOCKS5 to Forge Android Banking Pivots
1 Min Read
Share

TrickMo Variant Harnesses TON C2 for Android Banking Attacks

The latest TrickMo Android banking trojan, identified by ThreatFabric between ↓ 2 months, now routes commands through The Open Network (TON) and employs SOCKS5 proxies to create resilient network pivots on compromised devices.

Target Landscape Expands Across Europe

Researchers observed active campaigns against users of banking apps and cryptocurrency wallets in ↑ 3 nations – France, Italy and Austria – where victims report unauthorized transactions.

“The integration of TON C2 markedly raises the operational stealth of TrickMo, complicating detection for conventional security tools,” said a senior analyst at Reuters.

Technical analysis reveals that the malware loads a runtime‑generated APK module (dex.module) before establishing the proxy tunnel, allowing threat actors to relay traffic and exfiltrate credentials.

Security teams are advised to monitor anomalous TOR‑like traffic and enforce multi‑factor authentication on financial platforms, as highlighted in a recent Bloomberg briefing.


Intel provided by Kaelen Frost (Lead Cybersecurity Analyst).

Global Data Feed

More from this Intel

StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

Aug 11, 2026
Water System Attacks Surge Across U.S., Iran Suspected

Water System Attacks Surge Across U.S., Iran Suspected

Aug 11, 2026
Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Aug 11, 2026
GhostJacking Reveals Critical Gaps in AI Identity Governance

GhostJacking Reveals Critical Gaps in AI Identity Governance

Aug 11, 2026
Atlassian Rovo data breach exposes Jira and Confluence files to hackers

Atlassian Rovo data breach exposes Jira and Confluence files to...

Aug 09, 2026
Can Your Email Ever Be as Secure as Your Texts? The Case for End-to-End Encrypted Email

Can Your Email Ever Be as Secure as Your Texts?...

Aug 08, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.