Cybersecurity researchers have identified a sophisticated new variant of Android malware that represents a significant evolution in threats targeting mobile users. This latest incarnation of the TrickMo banking trojan family combines traditional credential-stealing capabilities with advanced blockchain-based communication techniques designed to evade detection and analysis.
Dubbed TrickMo.C by security firm ThreatFabric, which has been tracking the malware family since January 2026, this variant specifically targets Android users across Europe, with victims concentrated in France, Italy, and Austria. The malware distinguishes itself through its clever disguise, masquerading as popular social media and entertainment applications – particularly TikTok and various streaming services – to trick users into installation.
Once installed on a device, TrickMo.C establishes a comprehensive surveillance and data theft operation. The malware creates phishing overlays that capture login credentials and other sensitive information when users interact with what they believe to be legitimate applications. Beyond credential harvesting, the malicious software logs keystrokes, touch inputs, and screen activity, while also capable of live-streaming device contents to remote attackers.
One of the malware’s most concerning capabilities is its ability to interfere with security protocols. TrickMo.C can suppress one-time password (OTP) notifications, manipulate clipboard contents, filter notifications to hide security alerts, and surreptitiously capture screenshots – all techniques designed to facilitate unauthorized access to banking accounts, cryptocurrency wallets, and other financial instruments while keeping victims unaware of the compromise.
What truly sets this variant apart from previous iterations is its communication infrastructure. Rather than relying on conventional command-and-control servers that can be identified and shut down by security professionals, TrickMo.C utilizes the TON (Telegram Open Network) blockchain for its communications. This decentralized peer-to-peer network, originally developed within the Telegram ecosystem, provides the malware with a resilient and difficult-to-trace communication channel.
The operators employ ADNL addresses routed through an embedded native TON proxy running on the infected device, creating an encrypted overlay network that masks the true destination of communications. This approach makes traditional malware disruption techniques significantly less effective, as there are no central servers to seize or domain names to sinkhole.
Security experts note that the deployment of TrickMo.C appears to involve multiple distribution channels, including third-party app repositories, Telegram groups, social media platforms, and traditional phishing campaigns. The malware may also spread through search engine optimization poisoning techniques that manipulate search results to promote malicious applications.
For users, the emergence of this variant underscores the evolving nature of mobile threats and the importance of maintaining vigilant security practices. Experts recommend installing applications only from official app stores, carefully reviewing app permissions before installation, keeping operating systems and security software up to date, and remaining skeptical of unsolicited links or attachments, even when they appear to come from trusted sources.
As malware developers continue to innovate with techniques like blockchain-based communications, the cybersecurity landscape becomes increasingly complex. The TrickMo.C variant serves as a reminder that effective digital protection requires both technical safeguards and informed user behavior to combat ever-more-sophisticated threats targeting mobile devices.


