:

TRICKMO BANKER MALWARE NOW USES TON BLOCKCHAIN

AI DESK1 MIN READ
MON, MAY 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new variant of TrickMo Android banking malware is leveraging The Open Network (TON) blockchain for command-and-control communications. The malware, discovered in campaigns targeting European users, introduces expanded functionality while using blockchain infrastructure to evade detection.

TrickMo, a known Android banking trojan, has evolved to incorporate TON blockchain technology for its C2 infrastructure. This shift represents an escalation in evasion tactics, as blockchain-based communications are harder to intercept and block through traditional security measures. The updated variant introduces new commands alongside its existing banking credential theft capabilities. Security researchers tracking the malware note that European users remain primary targets, with distribution occurring through established infection chains. The adoption of TON for covert communications reflects a broader trend among malware operators seeking resilience against network-level defenses. Unlike centralized C2 servers, blockchain-based infrastructure distributes command delivery across a decentralized network, complicating takedown efforts. Security firms recommend users in affected regions exercise caution with app installations and enable banking app protections. Organizations should monitor for TrickMo indicators and consider TON blockchain communication patterns as part of threat detection strategies.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

MAY 29Industry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

MAY 29Security Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

MAY 29Industry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

MAY 29Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.