Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » TrickMo Android Malware Uses TON for Stealth Attacks

TrickMo Android Malware Uses TON for Stealth Attacks

New Variant Targets Banking and Crypto Wallet Users

Kelly Cromley by Kelly Cromley
May 11, 2026
in Market News, News
Reading Time: 3 mins read
0
The Open Network (TON)

A newly identified version of the TrickMo Android banking malware has emerged with expanded capabilities and a stealth-focused communication system that leverages The Open Network (TON). Cybersecurity researchers revealed that the updated malware strain is targeting Android users across several European countries, including France, Italy, and Austria, while focusing on banking credentials and cryptocurrency wallet information.

The malware, tracked as Trickmo.C by cybersecurity firm ThreatFabric, has reportedly been under observation since January. Researchers noted that the latest version disguises itself as popular applications such as TikTok clones and streaming services in an effort to trick users into installing infected software on their devices.

TON Integration Makes Detection More Difficult

One of the most significant developments in the new TrickMo variant is its adoption of TON-based command-and-control communications. Researchers explained that the malware uses.ADNL addresses are routed through a local TON proxy embedded directly on infected devices. This approach allows operators to conceal the real location of their infrastructure and avoid traditional tracking methods.

TON, originally associated with the Telegram ecosystem, functions as a decentralized peer-to-peer network that enables encrypted communication through an overlay network rather than relying on publicly exposed servers. Instead of standard domains, TON utilizes 256-bit identifiers, making it substantially harder for investigators and security teams to identify, block, or dismantle malicious infrastructure.

The latest TrickMo variant integrates TON-based command-and-control communication, significantly improving its ability to evade detection and resist infrastructure takedowns.

ThreatFabric researchers explained that traditional domain-based disruption methods become largely ineffective because the malware operators do not depend on the public DNS system. Instead, communications remain hidden within TON’s encrypted network traffic, which appears similar to regular TON-enabled application activity.

Malware Gains Expanded Offensive Capabilities

TrickMo was initially discovered in September 2019 and has remained in continuous development ever since. Previous investigations by cybersecurity company Zimperium in October 2024 identified dozens of malware variants delivered through multiple droppers and linked to numerous command-and-control infrastructures worldwide.

The malware operates through a modular two-stage architecture. The first stage consists of a host APK responsible for loading the malware and maintaining persistence on the infected device. The second stage downloads additional modules that carry out malicious operations.

The banking trojan is capable of stealing sensitive information through phishing overlays, keylogging, screen recording, live screen streaming, SMS interception, and clipboard manipulation. It can also suppress one-time password notifications, filter device notifications, and capture screenshots, giving attackers extensive control over compromised devices.

The latest version introduces several additional commands and networking features, including DNS lookup, ping execution, telnet access, traceroute functionality, SSH tunneling, remote and local port forwarding, as well as authenticated SOCKS5 proxy support.

The newly added networking and tunneling functions provide attackers with enhanced remote access and greater flexibility for maintaining covert operations on infected Android devices.

Researchers also identified traces of the Pine runtime hooking framework, previously used for intercepting networking and Firebase-related operations. However, no active hooks were found during the latest analysis. Additionally, the malware requests extensive NFC-related permissions and reports NFC capabilities back to operators, although researchers did not observe any currently active NFC exploitation features.

Android Users Urged to Exercise Caution

Cybersecurity experts continue to warn Android users against downloading applications from unofficial sources. Security professionals recommended limiting installed applications, relying only on reputable publishers, and ensuring that Google Play Protect remains enabled at all times.

Researchers warned that malware campaigns disguised as trusted entertainment and social media applications continue to pose a growing threat to banking and cryptocurrency users worldwide.

As mobile banking and digital asset adoption continue expanding globally, advanced malware operations such as TrickMo highlight the increasing sophistication of cybercriminal tactics targeting financial data and cryptocurrency holdings.

Previous Post

UBOX and ClawWorks Advance AI Agent Economies in Web3

Next Post

Okratech and Delphi AI Bring Predictive Intelligence to Web3

Related Posts

BYC Ventures

BYC Ventures and CeQureX Advance Quantum-Safe Blockchain Security

by Kelly Cromley
Jun 25, 2026
0

Blockchain infrastructure provider BYC Ventures has entered into a formal partnership with CeQureX, a Taipei-based cybersecurity firm, to strengthen its...

funton ai

Funton.ai and Echobit Partner to Expand Blockchain Gaming

by Kelly Cromley
Jun 25, 2026
0

Funton.ai, an artificial intelligence-powered decentralized multi-chain gaming network, has announced a strategic partnership with Echobit Exchange in a move designed...

treno scope

Treno Scope Launches $1M Program for Web3 Developers

by Kelly Cromley
Jun 25, 2026
0

Treno Scope, a leading Web3 market data infrastructure provider in Southeast Asia, has unveiled its Data for All developer empowerment...

noos

Noos and M3 DAO Unite to Advance AI-Powered Web3 Ecosystems

by Kelly Cromley
Jun 25, 2026
0

Noos, a next-generation AI infrastructure platform centered on verifiability and transparency, has announced a partnership with M3 DAO, a community-governed...

ethlabs

Ethlabs Launches to Advance Ethereum Institutional Adoption

by Kelly Cromley
Jun 25, 2026
0

A team of five former Ethereum Foundation researchers has launched Ethlabs, a new independent nonprofit research and development organization dedicated...

b.ai

B.AI and imToken Join Forces to Simplify Web3 AI Access

by Kelly Cromley
Jun 25, 2026
0

B.AI, an advanced artificial intelligence platform focused on Web3 users, has announced a strategic partnership with imToken, a widely used...

Next Post
okratech

Okratech and Delphi AI Bring Predictive Intelligence to Web3

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

BYC Ventures
Market News

BYC Ventures and CeQureX Advance Quantum-Safe Blockchain Security

by Kelly Cromley
Jun 25, 2026
funton ai
Market News

Funton.ai and Echobit Partner to Expand Blockchain Gaming

by Kelly Cromley
Jun 25, 2026
treno scope
Market News

Treno Scope Launches $1M Program for Web3 Developers

by Kelly Cromley
Jun 25, 2026
noos
Market News

Noos and M3 DAO Unite to Advance AI-Powered Web3 Ecosystems

by Kelly Cromley
Jun 25, 2026
ethlabs
Ethereum News

Ethlabs Launches to Advance Ethereum Institutional Adoption

by Kelly Cromley
Jun 25, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.