Cybersecurity researchers report a new variant of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). ThreatFabric observes the update being active between January and February 2026. The variant is described as routing attacker-controlled traffic through TON infrastructure and using network features including SOCKS5, creating what researchers call “network pivots” that help redirect communications. The reports state that this version is targeting users of banking services and cryptocurrency wallets in France, Italy, and Austria. The trojan’s behavior is also characterized as relying on runtime-loaded components within the app, described as a dex.module, which can support modular or updated functionality. Across the coverage, the central point is that the new TrickMo release changes how it reaches its C2, shifting to TON as part of its communications approach. While the outlets differ slightly in phrasing and emphasis, both attribute discovery to ThreatFabric and describe the same high-level capabilities: a TrickMo Android banking trojan variant, active in early 2026, using TON for C2 and associated routing techniques to reach victims’ devices.