Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » TrickMo Android Malware Uses TON for Stealth Attacks

TrickMo Android Malware Uses TON for Stealth Attacks

New Variant Targets Banking and Crypto Wallet Users

Kelly Cromley by Kelly Cromley
May 11, 2026
in Market News, News
Reading Time: 3 mins read
0
The Open Network (TON)

A newly identified version of the TrickMo Android banking malware has emerged with expanded capabilities and a stealth-focused communication system that leverages The Open Network (TON). Cybersecurity researchers revealed that the updated malware strain is targeting Android users across several European countries, including France, Italy, and Austria, while focusing on banking credentials and cryptocurrency wallet information.

The malware, tracked as Trickmo.C by cybersecurity firm ThreatFabric, has reportedly been under observation since January. Researchers noted that the latest version disguises itself as popular applications such as TikTok clones and streaming services in an effort to trick users into installing infected software on their devices.

TON Integration Makes Detection More Difficult

One of the most significant developments in the new TrickMo variant is its adoption of TON-based command-and-control communications. Researchers explained that the malware uses.ADNL addresses are routed through a local TON proxy embedded directly on infected devices. This approach allows operators to conceal the real location of their infrastructure and avoid traditional tracking methods.

TON, originally associated with the Telegram ecosystem, functions as a decentralized peer-to-peer network that enables encrypted communication through an overlay network rather than relying on publicly exposed servers. Instead of standard domains, TON utilizes 256-bit identifiers, making it substantially harder for investigators and security teams to identify, block, or dismantle malicious infrastructure.

The latest TrickMo variant integrates TON-based command-and-control communication, significantly improving its ability to evade detection and resist infrastructure takedowns.

ThreatFabric researchers explained that traditional domain-based disruption methods become largely ineffective because the malware operators do not depend on the public DNS system. Instead, communications remain hidden within TON’s encrypted network traffic, which appears similar to regular TON-enabled application activity.

Malware Gains Expanded Offensive Capabilities

TrickMo was initially discovered in September 2019 and has remained in continuous development ever since. Previous investigations by cybersecurity company Zimperium in October 2024 identified dozens of malware variants delivered through multiple droppers and linked to numerous command-and-control infrastructures worldwide.

The malware operates through a modular two-stage architecture. The first stage consists of a host APK responsible for loading the malware and maintaining persistence on the infected device. The second stage downloads additional modules that carry out malicious operations.

The banking trojan is capable of stealing sensitive information through phishing overlays, keylogging, screen recording, live screen streaming, SMS interception, and clipboard manipulation. It can also suppress one-time password notifications, filter device notifications, and capture screenshots, giving attackers extensive control over compromised devices.

The latest version introduces several additional commands and networking features, including DNS lookup, ping execution, telnet access, traceroute functionality, SSH tunneling, remote and local port forwarding, as well as authenticated SOCKS5 proxy support.

The newly added networking and tunneling functions provide attackers with enhanced remote access and greater flexibility for maintaining covert operations on infected Android devices.

Researchers also identified traces of the Pine runtime hooking framework, previously used for intercepting networking and Firebase-related operations. However, no active hooks were found during the latest analysis. Additionally, the malware requests extensive NFC-related permissions and reports NFC capabilities back to operators, although researchers did not observe any currently active NFC exploitation features.

Android Users Urged to Exercise Caution

Cybersecurity experts continue to warn Android users against downloading applications from unofficial sources. Security professionals recommended limiting installed applications, relying only on reputable publishers, and ensuring that Google Play Protect remains enabled at all times.

Researchers warned that malware campaigns disguised as trusted entertainment and social media applications continue to pose a growing threat to banking and cryptocurrency users worldwide.

As mobile banking and digital asset adoption continue expanding globally, advanced malware operations such as TrickMo highlight the increasing sophistication of cybercriminal tactics targeting financial data and cryptocurrency holdings.

Previous Post

UBOX and ClawWorks Advance AI Agent Economies in Web3

Next Post

Okratech and Delphi AI Bring Predictive Intelligence to Web3

Related Posts

hodl1

HODL1 and Startale Partner to Advance Ethereum and Stablecoins

by Kelly Cromley
Jun 8, 2026
0

Japanese Ethereum-focused financial infrastructure company HODL1, Inc. has entered into a memorandum of understanding with Singapore-based Web3 technology firm Startale...

Travala.com

Travala Launches AI Hotel Booking With USDC on Base

by Kelly Cromley
Jun 8, 2026
0

Singapore-based travel platform Travala has introduced a new artificial intelligence-powered hotel booking protocol that integrates USDC payments on Coinbase’s Base...

hecto walletone

Hecto WalletOne Leads Stablecoin Payment Pilot With Sui and ItemBay

by Kelly Cromley
Jun 8, 2026
0

Hecto WalletOne, a blockchain wallet infrastructure provider operating under Hecto Innovation, has entered into a four-party memorandum of understanding with...

crypto burger

Crypto Burger and ENI Join Forces to Accelerate Enterprise Blockchain Adoption

by Kelly Cromley
Jun 8, 2026
0

Crypto Burger, a well-known Web3-focused media organization, has entered into a partnership with ENI, a modular Layer-1 blockchain network, in...

tokenai

TokenAi Unveils Unified Trading Ecosystem for Digital and Traditional Assets

by Kelly Cromley
Jun 8, 2026
0

TokenAi, a Hong Kong-based on-chain aggregated trading firm, has announced a new initiative aimed at strengthening the connection between decentralized...

slide fun

Slide.fun Integrates SportixAI to Enhance Web3 Intelligence

by Kelly Cromley
Jun 7, 2026
0

Slide.fun, a decentralized gamified platform built on blockchain technology, has announced a strategic partnership with SportixAI, an artificial intelligence-powered sports...

Next Post
okratech

Okratech and Delphi AI Bring Predictive Intelligence to Web3

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

hodl1
Market News

HODL1 and Startale Partner to Advance Ethereum and Stablecoins

by Kelly Cromley
Jun 8, 2026
Travala.com
Market News

Travala Launches AI Hotel Booking With USDC on Base

by Kelly Cromley
Jun 8, 2026
hecto walletone
Market News

Hecto WalletOne Leads Stablecoin Payment Pilot With Sui and ItemBay

by Kelly Cromley
Jun 8, 2026
crypto burger
Market News

Crypto Burger and ENI Join Forces to Accelerate Enterprise Blockchain Adoption

by Kelly Cromley
Jun 8, 2026
tokenai
Market News

TokenAi Unveils Unified Trading Ecosystem for Digital and Traditional Assets

by Kelly Cromley
Jun 8, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.