Loading article…

New TrickMo C variant routes command‑and‑control through TON’s .adnl network, evading domain takedowns and turning phones into programmable pivots, targeting
A new TrickMo Android banking trojan variant began using The Open Network (TON) blockchain for its command‑and‑control (C2) traffic, making traditional domain takedowns ineffective [1]. The malware, labeled TrickMo C by ThreatFabric, was observed in active campaigns from January to February 2026 against banking and cryptocurrency wallet users in France, Italy and Austria [3].
The core change is the network layer. The host APK launches an embedded native TON proxy on a loopback port, then routes every HTTP request through that proxy to an .adnl hostname resolved inside the TON overlay rather than via public DNS [1]. Even the few remaining clearnet lookups are sent through a DNS‑over‑HTTPS endpoint, bypassing the device’s local resolver. Because the C2 endpoints exist only as TON identities, takedown efforts that rely on domain seizure or IP blocking lose their impact, and the traffic blends with legitimate TON application traffic [3].
Beyond stealth, the variant adds a network‑operative subsystem that lets attackers run commands such as curl, dnslookup, ping, telnet and traceroute from the compromised handset, effectively giving a shell‑equivalent for reconnaissance inside any corporate or home network the device is attached to [1]. An embedded SSH client and an authenticated SOCKS5 proxy allow the phone to act as a programmable network exit, routing malicious traffic through the victim’s IP and defeating IP‑based fraud detection on banking, e‑commerce and crypto platforms [3]. The malware still retains unused NFC permissions and the Pine hooking framework, suggesting future capability expansion.
TrickMo’s distribution continues to rely on deceptive dropper apps that masquerade as TikTok‑style content on Facebook ads, pulling a dynamically loaded “dex.module” APK at runtime [1]. The shift to a decentralized blockchain C2 marks a significant evolution from earlier versions that used socket.io‑based channels, indicating attackers are willing to adopt emerging infrastructure to stay ahead of defenders.
If the TON overlay can shield C2 traffic, defenders will need to look beyond domain‑based blocking and consider behavioral detection of anomalous TON‑related network activity on Android devices. The open question is how quickly security tools can adapt to monitor and mitigate malware that hides inside legitimate decentralized networks.
Coverage is mostly measured — 225 of 270 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Jun 16, 2026 · How we report
It tracks ether using the CoinDesk Ether Benchmark 4PM NY Settlement Rate.
Ethereum funds added $337.74 million in net inflows during July.
The expense ratio for MSSE is 0.14%.
No, Morgan Stanley does not retain any portion of the staking rewards earned by the trust.
Ethereum ETFs have reclaimed nearly two‑thirds of their June losses, whereas Bitcoin ETFs have recovered about 5% of theirs.