
New TrickMo Variant Uses TON for C2 Operations
CybersecurityMalwareBankingTrojansMobileSecurity
Cybersecurity researchers at ThreatFabric identified a new variant of the TrickMo Android banking trojan between January and February 2026, which leverages The Open Network (TON) for command-and-control (C2) operations. The malware targets users in France, Italy, and Austria, specifically those with banking and cryptocurrency wallet applications. This variant employs a runtime-loaded APK (dex.module) and incorporates SOCKS5 proxy functionality to establish network pivots. No CVE IDs or additional technical indicators were explicitly mentioned in the reported findings.