TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users in France, Italy, and Austria — Threadlinqs Intelligence
As of 2026-05-30, TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users in France, Italy, and Austria is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0494 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
ThreatFabric tracks a new TrickMo variant ('Trickmo.C') active since January 2026 that routes command-and-control through The Open Network (TON) using 256-bit .ADNL identities resolved by an embedded
TrickMo.C is the May-2026 evolution of the long-running TrickMo Android banking trojan, originally derived from the TrickBot ecosystem in 2019 and previously tracked by Cleafy, Cyble, and Zimperium through 2024-2025. ThreatFabric tracks the current campaign as 'Trickmo.C' and has observed active operations since January 2026, with installers distributed through SMS smishing, malicious overlay landing pages, and side-loaded APKs disguised as TikTok clones, premium streaming apps, and similar consumer-facing lures. Targeting telemetry concentrates in three Western European countries — France, Italy, and Austria — with overlay sets tailored to local retail banking, neobank, and cryptocurrency wallet apps.
The defining novelty of the 'C' variant is its abandonment of conventional HTTPS-over-DNS C2 in favor of The Open Network (TON) overlay routing. Each implant ships with an embedded local TON proxy that joins the TON peer-to-peer network on the infected device and resolves operator endpoints by their 256-bit Abstract Datagram Network Layer (ADNL) identities. Because ADNL addresses are public-key derived and resolved within the overlay, defenders cannot break the channel by seizing a domain or coercing a DNS provider; from the perspective of a network edge sensor the only observable traffic is encrypted TON peer traffic, indistinguishable in shape from any legitimate TON wallet, dApp, or storage client on the same device. This delivers a step-change in C2 resilience compared with prior TrickMo generations that relied on hardcoded fallback domains and CDN-fronted endpoints.
The trojan retains a two-stage modular architecture: a benign-looking host APK loader requests Android Accessibility Service privileges, then fetches a runtime offensive module that contains the bulk of fraud functionality. Capabilities inherited from prior TrickMo builds include HTML phishing overlays for banking and crypto login screens, full-screen lockscreen overlays, keystroke logging via Accessibility events, live screen streaming to the operator, screenshot capture, SMS and notification interception (including OTP suppression to defeat 2FA), clipboard sniffing and substitution (relevant to crypto address swapping), PIN and unlock-pattern theft, and contact-list and gallery exfiltration. New in 'Trickmo.C' is an operator-grade networking toolkit: an HTTP client (curl-equivalent), dnsLookup, ping, telnet, traceroute, SSH tunneling, both local and remote TCP port forwarding, and authenticated SOCKS5 proxy support. Combined with TON-routed C2, these capabilities turn each infected handset into a low-cost residential pivot point inside the victim's mobile network — useful for proxying further fraud, abusing trusted banking-app session state, or reaching internal services on a tethered or enterprise-managed device.
Two observable anti-analysis features warrant attention. First, the package declares extensive NFC permissions that are not exercised by any current code path; ThreatFabric assesses this as scaffolding for a future card-emulation or relay-fraud capability rather than an active feature. Second, the build ships a copy of the Pine runtime hooking framework that is present but currently inactive, signalling planned in-process API hooking for finer-grained Android Accessibility and banking-SDK manipulation. Defenders should treat these as forward-looking indicators rather than current TTPs.
There is no CVE associated with this threat — it is a malware-family campaign, not a vulnerability — and no CVSS score applies. Attribution remains 'Unknown' (financially motivated criminal operator(s)); ThreatFabric has not publicly linked Trickmo.C to a named TA, and earlier TrickMo waves have been operated by multiple unrelated actors leasing the codebase. Defenders should prioritize EDR on enrolled mobile devices, mobile threat defense (MTD) policies that flag sideloaded APKs and excessive Accessibility-Service grants, egress monitoring for TON ports (default 4
Weaknesses (CWE)
CWE-829, CWE-94, CWE-250, CWE-285, CWE-359
Target sectors: banking, financial, cryptocurrency, consumer-mobile, retail-banking, fintech
Target regions: France, Italy, Austria, Western Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1476, T1660, T1575, T1541, T1624, T1626, T1418, T1628, T1629, T1406