TrickMo Android banker variant leverages TON blockchain for covert C2 operations
Updated:
· First: 11.05.2026 12:03
· 📰 1 src / 1 articles
A new variant of the TrickMo Android banking trojan (codenamed Trickmo.C) has been observed in active campaigns across Europe, adopting The Open Network (TON) blockchain infrastructure for encrypted command-and-control communications. The malware masquerades as legitimate apps such as TikTok or streaming services and targets users in France, Italy, and Austria, focusing on banking credentials and cryptocurrency wallet access. TON’s decentralized peer-to-peer architecture, leveraging .ADNL addresses and local TON proxies, obscures operator infrastructure by routing traffic through an encrypted overlay network rather than traditional DNS-exposed servers, significantly complicating detection and takedown efforts by defenders.