Briefing

TrickMo Android banker adopts TON blockchain for covert comms

security
by Bill Toulas ·

Ensure Android devices only install apps from Google Play, limit app count, enable Play Protect, and monitor for TrickMo.C signatures.

What to do now

Ensure Android devices only install apps from Google Play, limit app count, enable Play Protect, and monitor for TrickMo.C signatures.

Summary

A new variant of the TrickMo Android banking malware, tracked as Trickmo.C, introduces TON blockchain for stealthy command‑and‑control communications. The malware uses .ADNL addresses routed through an embedded local TON proxy, a decentralized peer‑to‑peer network originally developed for Telegram, to hide IP addresses and ports, making traditional domain takedowns ineffective. Traffic‑pattern detection sees only TON traffic, which is encrypted and indistinguishable from other TON‑enabled applications. TrickMo remains a modular two‑stage design, with a host APK loader and a runtime‑downloaded APK module that implements offensive functionality. The latest variant adds commands such as curl, dnsLookup, ping, telnet, traceroute, SSH tunneling, remote and local port forwarding, and authenticated SOCKS5 proxy support. The malware also includes the Pine runtime hooking framework, though it is currently inactive, and reports NFC permissions without active NFC functionality. Users are advised to only download apps from Google Play, limit the number of installed apps, enable Play Protect, and ensure Play Protect is active at all times. The variant targets banking and cryptocurrency wallets in France, Italy, and Austria, and uses the TON overlay network to evade detection and takedown.

Key changes

  • TrickMo.C variant uses TON blockchain for C2 via .ADNL addresses and a local TON proxy.
  • TON hides IP addresses and ports, making domain takedowns ineffective.
  • Traffic‑pattern detection sees only encrypted TON traffic, indistinguishable from other TON apps.
  • New variant adds commands: curl, dnsLookup, ping, telnet, traceroute, SSH tunneling, remote and local port forwarding, authenticated SOCKS5 proxy support.
  • TrickMo remains a modular two‑stage design: host APK loader and runtime‑downloaded APK module.
  • Pine runtime hooking framework present but inactive; NFC permissions reported but no active NFC functionality.
  • Users advised to only download from Google Play, limit app count, enable Play Protect.
  • Variant targets banking and cryptocurrency wallets in France, Italy, and Austria.

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting