Cybersecurity researchers report a new variant of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). ThreatFabric observes the update being active between January and February 2026. The variant is described as routing attacker-controlled traffic through TON infrastructure and using network features including SOCKS5, creating what researchers call “network pivots” that help redirect communications. The reports state that this version is targeting users of banking services and cryptocurrency wallets in France, Italy, and Austria. The trojan’s behavior is also characterized as relying on runtime-loaded components within the app, described as a dex.module, which can support modular or updated functionality. Across the coverage, the central point is that the new TrickMo release changes how it reaches its C2, shifting to TON as part of its communications approach. While the outlets differ slightly in phrasing and emphasis, both attribute discovery to ThreatFabric and describe the same high-level capabilities: a TrickMo Android banking trojan variant, active in early 2026, using TON for C2 and associated routing techniques to reach victims’ devices.
TrickMo Android banking trojan variant reported using TON for command-and-control
Cybersecurity researchers report a new variant of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). ThreatFabric observes the update being active betwee...
- Researchers from ThreatFabric report a new TrickMo Android trojan variant active between January and February 2026.
- The variant uses The Open Network (TON) for command-and-control (C2).
- The reported implementation includes SOCKS5-based routing to create network “pivots.”
- Targets include banking and cryptocurrency wallet users in France, Italy, and Austria.
- The trojan is described as using runtime-loaded app components (dex.module).
Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. "TrickMo relies on a runtime-loaded APK (dex.module),
3 months agoThreatFabric finds new TrickMo Android banking trojan variant routing C2 through The Open Network
3 months ago
Man sets himself on fire in lobby of Google office in Lower Manhattan
A man sets himself on fire in the lobby of a Google office building in Lower Manhattan, prompting an emergency response....
Apple TV raises U.S. subscription prices to $14.99 per month
Apple is increasing the price of its Apple TV streaming subscription in the United States. Multiple outlets report the m...
Experts praise GTA 6’s real-time visuals, noting 30FPS focus and ray tracing implementation
Rockstar’s first major GTA 6 gameplay reveal is drawing praise from technology analysts for its real-time rendering and...