IntelNexus
FeedMapBoardBountiesBrief
Sign InDrop IntelDrop
Feed/New TrickMo Variant Uses TON C2 and SOCK
HIGHCYBERFREE

New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

Provenance𝕏 Tweet5 viewsMay 14, 2026

Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. "TrickMo relies on a runtime-loaded APK (dex.module), Source: The Hacker News

TrickMo Android, FR
#hacker#security#breach#crypto

AI Credibility Assessment

66%
ANONYMOUS
Loading discussion…
click ↩ reply on any comment to fight back
← Back to Feed