A new TrickMo Android banking trojan variant is targeting banking, fintech, wallet, and authenticator app users in France, Italy, and Austria, with campaigns distributing the malware through fake TikTok and streaming apps promoted on social media. Researchers said the strain is a major platform redesign of the existing malware rather than a new family, preserving TrickMo’s core device-takeover features after accessibility abuse, including phishing overlays, keylogging, screen recording and streaming, SMS and notification interception, OTP suppression, clipboard manipulation, screenshot capture, and full remote control.
The most significant change is TrickMo’s migration of command-and-control traffic from conventional internet infrastructure to The Open Network (TON) using .adnl endpoints and an embedded local TON proxy, making tracing and takedowns more difficult. The malware also adds network-reconnaissance and tunneling functions that let attackers use compromised Android devices as programmable traffic-exit nodes, including support for SSH port forwarding and authenticated SOCKS5 proxying, alongside commands such as curl, DNS lookup, ping, traceroute, telnet, and HTTP probing. Researchers also found dormant components tied to the Pine hooking framework and declared NFC permissions, indicating preparation for future capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric reported a new 2026 TrickMo variant, assessed as a major platform overhaul rather than a new malware family, while noting it retains core device-takeover capabilities such as accessibility abuse, phishing overlays, keylogging, screen streaming, SMS interception, and remote control. The researchers also observed dormant Pine hooking components and NFC-related permissions suggesting preparation for future features.
The 2026 variant introduced reconnaissance and tunneling functions including DNS lookup, ping, traceroute, HTTP probing/curl, SSH tunneling and port forwarding, and authenticated SOCKS5 proxying. These additions allow infected Android devices to act as programmable traffic-exit nodes for fraud and evasion.
In the 2026 campaign, TrickMo's operators migrated primary command-and-control communications from conventional internet infrastructure to The Open Network using .adnl endpoints and an embedded local TON proxy. This architectural change improved stealth and resilience against tracing and takedown.
Between January and February 2026, operators ran campaigns using a new TrickMo variant against banking and cryptocurrency wallet users in France, Italy, and Austria. The malware was distributed via fake TikTok and streaming-themed Android apps, including a deceptive app named "Live Streaming," promoted through Facebook campaigns.
In October 2024, prior research by Zimperium reported 40 TrickMo variants delivered through 16 droppers and supported by 22 distinct command-and-control infrastructures, showing the malware's continued development before the 2026 redesign.
The TrickMo Android banking trojan was first seen in the wild in 2019, establishing the malware family later associated with banking credential theft and device takeover activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethreatfabric.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.