New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network… | HappeningNow.news

Cybersecurity · 47 views

New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2).

Source AI Summary Published May 12, 2026 Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 47 Community interest
Brief read Under 1 min brief 69 words

AI Summary

Cybersecurity researchers identified a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command‑and‑control. ThreatFabric observed the variant between January and February 2026. It has been actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. The trojan’s use of TON and SOCKS5 enables it to pivot through Android networks. No further details on its capabilities or future actions were provided.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at The Hacker News

Coverage Context

Part of C2 coverage 36 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page