New Android Malware Variant Uses Blockchain Technology to Evade Detection

Cybersecurity researchers have identified a sophisticated new variant of Android malware that represents a significant evolution in threats targeting mobile users. This latest incarnation of the TrickMo banking trojan family combines traditional credential-stealing capabilities with advanced blockchain-based communication techniques designed to evade detection and analysis.

Dubbed TrickMo.C by security firm ThreatFabric, which has been tracking the malware family since January 2026, this variant specifically targets Android users across Europe, with victims concentrated in France, Italy, and Austria. The malware distinguishes itself through its clever disguise, masquerading as popular social media and entertainment applications – particularly TikTok and various streaming services – to trick users into installation.

Once installed on a device, TrickMo.C establishes a comprehensive surveillance and data theft operation. The malware creates phishing overlays that capture login credentials and other sensitive information when users interact with what they believe to be legitimate applications. Beyond credential harvesting, the malicious software logs keystrokes, touch inputs, and screen activity, while also capable of live-streaming device contents to remote attackers.

One of the malware’s most concerning capabilities is its ability to interfere with security protocols. TrickMo.C can suppress one-time password (OTP) notifications, manipulate clipboard contents, filter notifications to hide security alerts, and surreptitiously capture screenshots – all techniques designed to facilitate unauthorized access to banking accounts, cryptocurrency wallets, and other financial instruments while keeping victims unaware of the compromise.

What truly sets this variant apart from previous iterations is its communication infrastructure. Rather than relying on conventional command-and-control servers that can be identified and shut down by security professionals, TrickMo.C utilizes the TON (Telegram Open Network) blockchain for its communications. This decentralized peer-to-peer network, originally developed within the Telegram ecosystem, provides the malware with a resilient and difficult-to-trace communication channel.

The operators employ ADNL addresses routed through an embedded native TON proxy running on the infected device, creating an encrypted overlay network that masks the true destination of communications. This approach makes traditional malware disruption techniques significantly less effective, as there are no central servers to seize or domain names to sinkhole.

Security experts note that the deployment of TrickMo.C appears to involve multiple distribution channels, including third-party app repositories, Telegram groups, social media platforms, and traditional phishing campaigns. The malware may also spread through search engine optimization poisoning techniques that manipulate search results to promote malicious applications.

For users, the emergence of this variant underscores the evolving nature of mobile threats and the importance of maintaining vigilant security practices. Experts recommend installing applications only from official app stores, carefully reviewing app permissions before installation, keeping operating systems and security software up to date, and remaining skeptical of unsolicited links or attachments, even when they appear to come from trusted sources.

As malware developers continue to innovate with techniques like blockchain-based communications, the cybersecurity landscape becomes increasingly complex. The TrickMo.C variant serves as a reminder that effective digital protection requires both technical safeguards and informed user behavior to combat ever-more-sophisticated threats targeting mobile devices.

spot_imgspot_img

Subscribe

Related articles

Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison

Latvian national sentenced to 8.5 years for Karakurt ransomware negotiator role in $56M+ extortion scheme.

Google now offers up to $1.5 million for some Android exploits

Google overhauls Android and Chrome vulnerability rewards, offering up to $1.5 million for complex exploits while adjusting AI-discoverable flaw payouts.

Test Post Updated

This test post has been updated.

Weekly Deals: iPhone Air and iPhone 17 Price Cuts, Galaxy S26 and Pixel 10 Series on Sale

This Week's Best Smartphone DealsThe flagship smartphone market is...

Apple Unveils 2026 Pride Edition Sport Loop — A Rainbow Woven for Every Identity

A Band That Celebrates the Full SpectrumApple has launched...
spot_imgspot_img