Cybersecurity · 47 views
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2).
AI Summary
Cybersecurity researchers identified a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command‑and‑control. ThreatFabric observed the variant between January and February 2026. It has been actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. The trojan’s use of TON and SOCKS5 enables it to pivot through Android networks. No further details on its capabilities or future actions were provided.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Cyber exec arrested in case allegedly tied to ShinyHunters hackersContinue reading
- ARTEX AI, Claude agents used in cyberattacks on South Korean banksContinue reading
- Criminal IP Introduces AITEM as the Next Evolution of Attack Surface ManagementContinue reading
- The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn'tContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow