
0
Technology
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
May 12, 2026
Scroll
Posted 3 hours ago by
Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. TrickMo relies on a runtime-loaded APK (dex.module),

The Hacker News
Coverage and analysis from United States of America. All insights are generated by our AI narrative analysis engine.
United States of America
Bias: Unknown