TrickMo is an Android banking trojan associated with TrickBot-enabled banking-fraud campaigns. First identified in 2019, it initially targeted German banking users to steal transaction-authentication numbers and bypass SMS- and application-based two-factor authentication. Early infections were promoted through web injects on TrickBot-infected Windows systems during online-banking sessions, which prompted victims to install sideloaded Android applications posing as security software. Later variants have also masqueraded as popular browser and streaming applications.
TrickMo abuses Android Accessibility Services to automate permission approval, interact with device interfaces, monitor targeted applications, and execute operator-directed actions. It inventories installed applications and device configuration to identify valuable targets, then uses WebView-based overlay attacks to capture credentials from banking, fintech, cryptocurrency-wallet, email, commerce, social-media, and authentication applications. It can intercept, read, send, and delete SMS messages, enabling theft and concealment of one-time passwords and transaction codes. It can also collect photographs, videos, call logs, device data, and Accessibility event logs, and transmit collected information to command-and-control infrastructure over HTTP.
The malware uses broadcast receivers tied to screen and SMS events to trigger execution and support persistence. It can request to become the default SMS application, resist removal, disable notifications, unlock the device, change its icon, invoke USSD requests, and download additional Android modules at runtime. Its Accessibility-driven click automation and on-device interaction enable device takeover and direct manipulation of legitimate financial and authentication app sessions, helping operators evade conventional fraud controls and multi-factor authentication protections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is also capable of gaining persistence on infected Android devices by registering a receiver that will listen for android.intent.action.SCREEN_ON and android.provider.Telephony.SMS_DELIVER broadcasts to restart itself after a reboot when the screen turns on or an SMS is received.
The malware is also capable of gaining persistence on infected Android devices by registering a receiver that will listen for android.intent.action.SCREEN_ON and android.provider.Telephony.SMS_DELIVER broadcasts to restart itself after a reboot when the screen turns on or an SMS is received.
Dropper apps containing the malware masquerade as adult versions of TikTok, whereas the actual malware impersonates Google Play Services
This allows the Android Trojan to delete SMS messages it forwards to its masters so that the victims are never aware that their devices received a text message with a 2FA code from their banks.
it was recently updated, in January 2020, with code that checks if the malware is running on a rooted device or an emulator.
The host APK acts primarily as a launcher and persistence layer, while the offensive functionality is delivered separately through the dynamically loaded APK with package name " dex.module " fetched from operator infrastructure at runtime and injected into the running process.
Once installed on Android devices, the malware abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, and manipulate app sessions directly on the device.
Keylogging that captures typed text and field metadata correlated with the foreground package
After the infection, a webinject is deployed by Dreambot on the victim browsers and when that victims logs into the online banking service, credentials are intercepted to be later reused by the carder.
The Android app dubbed TrickMo ... is using a malicious Android application they developed to bypass two-factor authentication (2FA) protection used by various banks after stealing transaction authentication numbers.
dnsLookup deliberately uses the platform resolver rather than the bot's DoH path, so the operator learns what the device's network sees for a given name.
Monokle checks if the device is connected via Wi-Fi or mobile data; Pegasus for Android checks if the device is on Wi-Fi, a cellular network, and is roaming; TianySpy can check to see if Wi‑Fi is enabled; TERRACOTTA can check if the active network connection is metered; TrickMo can collect device network configuration information such as IMSI, IMEI, and Wi‑Fi connection state.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
Once installed on Android devices, the malware abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, and manipulate app sessions directly on the device.
Keylogging that captures typed text and field metadata correlated with the foreground package
The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy.
AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; BRATA can use both HTTP and WebSockets to communicate with the C2 server; LightSpy has used both HTTPS and Websockets to communicate with the C2.
An on-device SOCKS5 proxy with user-and-password authentication turns the infected handset into a per-request-routed network exit node.
The host APK acts primarily as a launcher and persistence layer, while the offensive functionality is delivered separately through the dynamically loaded APK with package name " dex.module " fetched from operator infrastructure at runtime and injected into the running process.
Once installed on Android devices, the malware abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, and manipulate app sessions directly on the device.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as a comparison to a separate Android banking-malware campaign using fake streaming-app lures.
Android banking malware that abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, manipulate app sessions, and enable device takeover within legitimate financial and authentication apps.
Android device takeover malware active since late 2019 that abuses accessibility services to hijack OTPs, phish for credentials, log keystrokes, record and stream screens, intercept SMS messages, and provide remote control of infected devices. The latest variant uses TON-based C2 and adds reconnaissance, SSH tunnelling, and SOCKS5 proxying to turn compromised phones into programmable network pivots and traffic-exit nodes.
Android banking malware that abuses accessibility services to take over devices, steal credentials, log keystrokes, intercept and suppress SMS and OTP notifications, record screens, enable live remote interaction, and route malicious traffic through the victim device using SSH tunnelling and an authenticated SOCKS5 proxy. The new variant also uses TON-based C2 and loads a runtime module named dex.module for remote-control functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.