{"id":891,"date":"2026-05-12T13:43:51","date_gmt":"2026-05-12T13:43:51","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=891"},"modified":"2026-05-12T13:43:51","modified_gmt":"2026-05-12T13:43:51","slug":"new-trickmo-variant-uses-ton-c2-and-socks5-to-create-android-network-pivots","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=891","title":{"rendered":"New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 12, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Mobile Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjbBy7H5qvorFUmJqREACqqxVC0ogVq88dP8wLyKyUPF9fCowpUSkb7foEsEPDALt0ccCpcJc6PXCJjFmQo0oX3furU-cYPULBa0-pjpiLGV04JD6kr4G0VIrvFoJo54WmgjU1YocsquA15N3hxDmwt4i82QpYdil7F4fI0SMFVv9YCkbqqGKjIi-dEmcIx\/s1700-e365\/tricks.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged a new version of the <strong>TrickMo<\/strong> Android banking trojan that uses The Open Network (TON) for command-and-control (C2).<\/p>\n<p>The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria.<\/p>\n<p>\u00abTrickMo relies on a runtime-loaded APK\u00a0 (dex.module), used also by the previous variant, but updated with new features adding new network-oriented functionality, including reconnaissance, SSH tunnelling, and SOCKS5 proxying capabilities that allow infected devices to function as programmable network pivots and traffic-exit nodes,\u00bb the Dutch mobile security company <a href=\"https:\/\/www.threatfabric.com\/blogs\/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>TrickMo is the name assigned to a device takeover (DTO) malware that&#8217;s been active in the wild since late 2019. It was first flagged by CERT-Bund and IBM X-Force, describing its ability to abuse Android&#8217;s accessibility services to hijack one-time passwords (OTPs).<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s also equipped with a wide range of features to phish for credentials, log keystrokes, record screen, facilitate live screen streaming, intercept SMS messages, essentially granting the operator complete remote control of the device.<\/p>\n<p>The latest versions, labeled TrickMo C, are distributed via phasing websites and dropper apps, the latter of which serve as a conduit for a dynamically loaded APK (\u00abdex.module\u00bb) that&#8217;s retrieved at runtime from attacker-controlled infrastructure. A notable shift in the architecture entails the use of the TON decentralized blockchain for stealthy C2 communications.<\/p>\n<p>\u00abTrickMo carries an embedded native TON proxy that the host APK starts on a loopback port at process start,\u00bb ThreatFabric said. \u00abThe bot&#8217;s HTTP client is wired through that proxy, so every outbound command-and-control request is addressed to an .adnl hostname and resolved through the TON overlay.\u00bb<\/p>\n<p>Dropper apps containing the malware masquerade as adult versions of TikTok, whereas the actual malware impersonates Google Play Services &#8211;<\/p>\n<ul>\n<li><a href=\"https:\/\/www.virustotal.com\/gui\/file\/01889a9ec2abecb73e5e8792be68a4e3bc7dcbe1c3f19ac06763682d63aa8c21\">com.app16330.core20461<\/a> or com.app15318.core1173 (Dropper)<\/li>\n<li>uncle.collop416.wifekin78 or nibong.lida531.butler836 (TrickMo)<\/li>\n<\/ul>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFZKSyOYh-8A_N96kM87oVcGaBo1V72axVpZNUDxei9obnpsskTgNaSWNA-hxOP0HBH2qjqsPiHCflUVQnF0rwiIN60Zw6pCCyVHLaLjHUUOnvOVVcKrB_vV-8rla7FKIGLYmRRyazfuY5e9g2RVilnHHeO5uRGARDixlWO-XPSESXNwWjYAdQAVEeiz3O\/s1700-e365\/trick.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFZKSyOYh-8A_N96kM87oVcGaBo1V72axVpZNUDxei9obnpsskTgNaSWNA-hxOP0HBH2qjqsPiHCflUVQnF0rwiIN60Zw6pCCyVHLaLjHUUOnvOVVcKrB_vV-8rla7FKIGLYmRRyazfuY5e9g2RVilnHHeO5uRGARDixlWO-XPSESXNwWjYAdQAVEeiz3O\/s1700-e365\/trick.png\" alt=\"\" border=\"0\" data-original-height=\"1080\" data-original-width=\"1920\"\/><\/a><\/div>\n<p>While previous iterations of \u00abdex.module\u00bb implemented the accessibility-driven remote control functionality through a socket.io-based channel, the new version utilizes a network-operative subsystem that turns the malware into a tool for managed foothold than a traditional banking trojan.<\/p>\n<p>The subsystem supports commands like curl, dnslookup, ping, telnet, and traceroute, giving the attacker a \u00abremote shell-equivalent for network reconnaissance from the victim&#8217;s network position, including any internal corporate or home network the device is currently associated with,\u00bb per ThreatFabric.<\/p>\n<p>Another important feature is a SOCKS5 proxy that turns the compromised device into a network exit node that routes malicious traffic, while defeating IP-based fraud-detection signatures on banking, e-commerce and cryptocurrency exchange services.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Furthermore, TrickMo includes two dormant features that bundle the Pine hooking framework and declare extensive NFC-related permissions. But neither of them are actually implemented. This likely indicates the core developers are looking to expand on the trojan&#8217;s capabilities in the future.\u00a0<\/p>\n<p>\u00abInstead of relying on conventional DNS and public internet infrastructure, the malware communicates through .adnl endpoints routed via an embedded local TON proxy, reducing the effectiveness of traditional takedown and network-blocking efforts while making the traffic blend with legitimate TON activity,\u00bb ThreatFabric said.<\/p>\n<p>\u00abThis latest variant also expands the operational role of infected devices through SSH tunnelling and authenticated SOCKS5 proxying, effectively turning compromised phones into programmable network pivots and traffic-exit nodes whose connections originate from the victim\u2019s own network environment.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 12, 2026Malware \/ Mobile Security Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The&hellip;<\/p>\n","protected":false},"author":1,"featured_media":892,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[281,1631,589,1632,1211,1630,1629,664],"class_list":["post-891","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-android","tag-create","tag-network","tag-pivots","tag-socks5","tag-ton","tag-trickmo","tag-variant"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=891"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/891\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/892"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}