Menu

Post image 1
Post image 2
1 / 2
0

TrickMo Android banker adopts TON blockchain for covert comms

DEV Community·Mark0·21 days ago
#sNEue1uZ
Reading 0:00
15s threshold

Mark0

TrickMo, a long-standing Android banking malware, has evolved with a new variant labeled 'Trickmo.C' targeting users across Europe. Disguised as popular applications like TikTok, the malware aims to steal sensitive banking credentials and cryptocurrency wallet data. This version introduces sophisticated evasion techniques, including the use of The Open Network (TON) for decentralized command-and-control (C2) communications.

By leveraging .ADNL addresses and an embedded TON proxy, the malware obscures its server infrastructure, making traditional domain takedowns and traffic analysis significantly harder. In addition to its core capabilities like screen recording and SMS interception, the new variant adds advanced networking tools such as SSH tunneling and SOCKS5 proxy support, marking a significant step up in its operational complexity.


Read Full Article

Read More