HomeSecurityTrickMo banking malware for Android adopts TON blockchain

TrickMo banking malware for Android adopts TON blockchain

A new variant of the TrickMo banking malware for Android, distributed through campaigns targeting users across Europe, introduces new commands and leverages the TON blockchain for covert command-and-control (C2) communications.

See also: Mobile malware: Why Android remains a target

TrickMo

TrickMo was first detected in September 2019 and has been continuously evolving since then, receiving regular upgrades.

In October 2024, Zimperium analyzed 40 variants of the malware, which were distributed via 16 droppers, communicated with 22 different command-and-control infrastructures, and targeted sensitive user data worldwide. The most recent variant was detected by ThreatFabric, which tracks it under the name “Trickmo.C.” Researchers have been observing this particular variant since January.

According to a report today by ThreatFabric, the malware disguises itself as apps like TikTok or streaming apps and targets banking apps and crypto wallets of users in France, Italy, and Austria.

The main new feature of the current variant is communication via the TON blockchain with the malware operators. This communication uses .ADNL that are routed through a built-in local TON proxy running on the infected device.

TON is a decentralized peer-to-peer network originally developed around the Telegram ecosystem that allows devices to communicate through an encrypted network overlay instead of publicly accessible servers on the internet.

TON uses a 256-bit identifier instead of a regular domain name, thus hiding the IP address and communication port. This makes it much more difficult to detect, block, or disable the actual server infrastructure.

See also: Horabot Banking Trojan: New campaign focusing on Mexico

TrickMo banking malware for Android adopts TON blockchain

TrickMo is a modular malware with a two-stage design: an initial APK acts as a loader and persistence mechanism, while a second APK module is downloaded at runtime and implements the offensive functions.

The malware targets banking credentials via phishing overlays and can perform keylogging,screen recording and live streaming, SMS interception, OTP notification hiding, clipboard modification, notification filtering, and screenshot capture.

ThreatFabric reports that the new variant also adds the following commands and capabilities:

  • curl
  • dnsLookup
  • ping
  • telnet
  • traceroute
  • SSH tunneling
  • remote port forwarding
  • local port forwarding
  • authenticated SOCKS5 proxy support

Researchers also identified the Pine runtime, which has been used in the past to interfere with network operations and Firebase. However, it currently remains inactive, as no active hooks have been installed.

TrickMo still declares extensive NFC access permissions and records NFC capabilities in telemetry data, but researchers did not detect any active functionality that leverages NFC.

See also: 6 new Android malware targets banking apps

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

TrickMo banking malware for Android adopts TON blockchain

Android users are advised to only download apps from Google Play, limit the number of apps installed on their devices, use apps only from trusted publishers, and keep Google Play Protect enabled at all times.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS