2026-05-13NOTABLETrickMo "TrickMo C", Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
TrickMo C
tool · tool:trickmo-c-2026
TrickMo variant ('TrickMo C'): Android banking trojan with C2 migrated to The Open Network blockchain, adding SOCKS5/SSH device-as-pivot; campaigns in FR/IT/AT.
Coverage
1
first 2026-05-13 → last 2026-05-13
Latest activity
2026-05-13
TrickMo "TrickMo C", Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH…
Peak priority
notable
1 notable
Targets
finance
sectors: finance · regions: europe
Sources cited
3
3 hosts
Defender insights
What each entry about TrickMo C tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Command and ControlProxy: Internal Proxy
Command and Control TA0011
T1090.001Proxy: Internal Proxy×1
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.
Evidence: 2026-05-13/trickmo-trickmo-c-android-banking-trojan-migrates-c2-to-the · ATT&CK page ↗
Entries about TrickMo C (1)
Where this entity is cited
Source distribution
- securityaffairs.com1 (33%)
- thehackernews.com1 (33%)
- threatfabric.com1 (33%)
All cited sources (3)
- securityaffairs.comSecurity Affairs, 2026-05-12https://securityaffairs.com/192003/malware/android-banking-trojan-trickmo-evolves-using-ton-network-for-c2.html
- thehackernews.comThe Hacker News, 2026-05-12https://thehackernews.com/2026/05/new-trickmo-variant-uses-ton-c2-and.html
- threatfabric.comThreatFabric, 2026-05-11https://www.threatfabric.com/blogs/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app