The new TrickMo variant shows how mobile banking malware is moving beyond credential theft into full network abuse. By using The Open Network, or TON, for stealthier command-and-control and adding SSH tunnelling plus SOCKS5 proxying, infected Android devices can become programmable network pivots and traffic-exit nodes. That means a compromised phone is no longer just a victim device; it can become attacker infrastructure sitting inside a home or corporate network. 

This is especially dangerous for banking, crypto, and enterprise environments because traffic can originate from the victim’s real network, helping attackers bypass IP-based fraud checks and making malicious activity look more legitimate. TrickMo’s existing capabilities, including accessibility abuse, credential phishing, OTP interception, keystroke logging, screen recording, and remote control, make it a serious device-takeover threat.

Users should avoid installing apps from links shared through social media or unofficial sites, especially apps pretending to be modified versions of popular platforms. Organizations should treat mobile devices as part of the attack surface, enforce mobile threat protection where possible, monitor suspicious proxy/VPN-like behaviour, and educate users that “friendly-looking” app downloads can quietly turn their device into someone else’s network tool.


Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. "TrickMo relies on a runtime-loaded APK (dex.module),

Source: New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots via The Hacker News — published 12 May 2026.