Briefing

New TrickMo Android Banking Trojan Variant Uses TON for Command‑and‑Control

security
by [email protected] (The Hacker News) ·

Disable TON‑based C2 traffic and update mobile security solutions.

What to do now

Disable TON‑based C2 traffic and update mobile security solutions.

Summary

Cybersecurity researchers have identified a new variant of the TrickMo Android banking trojan that leverages The Open Network (TON) for command‑and‑control communications. The variant was observed by ThreatFabric between January and February 2026, actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. TrickMo employs a runtime‑loaded APK module, known as dex.module, to inject malicious code into legitimate applications. The use of TON provides a decentralized and resilient C2 infrastructure, making detection more challenging. The trojan specifically targets financial applications, aiming to steal credentials and facilitate unauthorized transactions. No large‑scale data exfiltration has been reported, but the variant demonstrates an evolving threat landscape. Security teams should monitor for TON‑based C2 traffic and update mobile security solutions accordingly. The variant highlights the importance of monitoring for new banking trojans.

Key changes

  • New TrickMo variant uses TON for C2.
  • Active targeting France, Italy, Austria.
  • Observed Jan–Feb 2026.
  • Uses runtime‑loaded APK (dex.module).
  • Targets banking and crypto wallet users.
  • No large‑scale data exfiltration reported.
  • Demonstrates evolving threat landscape.
  • Requires monitoring TON traffic.

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting