TrickMo Android banking trojan variant with TON C2 and network pivots
Malware Activity
Summary
Hide ▲
Show ▼
A new TrickMo Android banking trojan variant now uses The Open Network (TON) for C2, turning infected phones into network pivots and traffic-exit nodes. It was observed between January and February 2026 while targeting banking and cryptocurrency wallet users in France, Italy, and Austria. The build adds reconnaissance, SSH tunnelling, and SOCKS5 proxying to extend the malware’s reach beyond credential theft. That shift makes compromised phones more useful for fraud evasion and network abuse.
Related Happenings
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
TrojPix air-gap covert channel turns video cables into a high-speed exfiltration path
Technical Analysis
H score20
First: 06.07.2026 11:50
Last: 06.07.2026 11:50
Sources 1
About this happening:
TrojPix introduces a new air-gap exfiltration technique that uses imperceptible pixel modulation and video cable emissions to move data out of isolated systems, ra...
TrojPix air-gap covert channel turns video cables into a high-speed exfiltration path
Technical AnalysisAbout this happening: TrojPix introduces a new air-gap exfiltration technique that uses imperceptible pixel modulation and video cable emissions to move data out of isolated systems, ra...
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
NFCShare Android malware spreads via fake banking-app updates
Malware Activity
H score21
First: 09.06.2026 01:11
Last: 09.06.2026 01:11
Sources 1
About this happening:
The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...
NFCShare Android malware spreads via fake banking-app updates
Malware ActivityAbout this happening: The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...
Timeline
-
12.05.2026 15:50 2 articles · 2mo ago
ThreatFabric discloses TrickMo TON-backed Android variant
Initial DisclosureThreatFabric disclosed a new TrickMo Android banking trojan variant observed between January and February 2026 that is targeting banking and cryptocurrency wallet users in France, Italy, and Austria. The malware uses The Open Network (TON) for command-and-control, relies on a runtime-loaded APK called dex.module, and adds reconnaissance, SSH tunnelling, and SOCKS5 proxying to turn infected devices into programmable network pivots and traffic-exit nodes.
Show sources
- New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots — thehackernews.com — 12.05.2026 15:50
- New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots — thehackernews.com — 12.05.2026 15:50