radar

ONE Sentinel

securitySecurity/THREATS/HIGH

TrickMo Android banker adopts TON blockchain for covert comms

sourceBleeping Computer
calendar_todayMay 11, 2026
schedule1 min read
lightbulb

EXECUTIVE SUMMARY

TrickMo Android Malware Leverages TON Blockchain for Covert Operations

Summary

A new variant of the TrickMo Android banking malware has been discovered, targeting users across Europe. This variant utilizes The Open Network (TON) blockchain for stealthy command-and-control communications.

Key Points

  • TrickMo is an Android banking malware targeting European users.
  • The malware variant introduces new commands for enhanced functionality.
  • It uses The Open Network (TON) blockchain to facilitate covert communications.
  • This approach helps the malware evade traditional detection methods.

Analysis

The adoption of the TON blockchain by TrickMo represents a significant evolution in malware communication strategies, highlighting the increasing sophistication of cyber threats. By leveraging blockchain technology, TrickMo can maintain a more resilient and stealthy command-and-control infrastructure, complicating detection and mitigation efforts by security professionals.

Conclusion

IT professionals should enhance their security protocols to detect and mitigate blockchain-based communication methods used by malware. Regular updates to security systems and awareness of emerging threats like TrickMo are essential to protect against sophisticated cyber threats.