s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.trickmo

📛 Threat Title

Malware family: TrickMo

Category: TrickMo First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.trickmo`. Printable name: TrickMo.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.trickmo VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.trickmo

IOC database

Type
domain
Value
apk.trickmo
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.trickmo

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.trickmo

References (1)

Remediations (10)

  • web:cyberpress.org

    Threat actors are rewriting the rulebook on mobile malware . Instead of simply building entirely new malicious tools, hackers are drastically re-engineering older threats to be virtually undetectable. A highly stealthy new variant of the TrickMo Android banking trojan has emerged, actively targeting banking, fintech, and crypto wallet users across France, Italy, and Austria. By completely ...

  • web:cybersecuritynews.com

    A dangerous Android banking malware known as TrickMo has resurfaced with a powerful new variant, and this time it is more stealthy, more capable, and harder to stop than ever before. The threat is actively targeting users of banking apps, digital wallets, and authenticator applications across Europe, putting financial data and account access at serious risk. The malware spreads through fake ...

  • web:dailysecurityreview.com

    Table of Contents ThreatFabric researchers have identified a new TrickMo Android banking trojan variant that routes command-and-control communications through The Open Network (TON) blockchain, marking the first documented deployment of decentralized blockchain infrastructure as a C2 channel in a major mobile banking malware family .

  • web:gbhackers.com

    TrickMo , the Android banking malware , has resurfaced with a significantly redesigned architecture, targeting banking, fintech, wallet, and authenticator applications.

  • web:netcrook.com

    A resurfaced Android malware family is shifting from noisy credential theft toward a more durable device-takeover model aimed at banking, fintech, wallet, and authenticator apps.

  • web:thehackernews.com

    A new TrickMo Android banking trojan variant uses TON blockchain infrastructure for stealthy command-and-control communications.

  • web:www.cleafy.com

    Explore Cleafy's analysis of a newly discovered TrickMo variant, revealing enhanced malware capabilities and critical endpoints used for storing stolen credentials and data from victims. Here is the latest threat analyst report.

  • web:www.firstpost.com

    The TrickMo virus was first identified and tracked between January and February 2026, and was regarded at the time as an Android banking trojan family virus under active monitoring. While occurrences of its attacks had died down over the past few months, a new version of the virus has recently resurfaced and begun disrupting established financial systems. The platform that forms the basis of ...

  • web:www.infosecurity-magazine.com

    A new variant of the TrickMo Android banking trojan has moved its primary command-and-control (C2) transport onto The Open Network (TON) Blockchain, routing communications through the decentralized overlay's .adnl identities to make traditional domain takedowns largely ineffective.

  • web:www.threatfabric.com

    Perseus is a new Device Takeover (DTO) malware family that specifically looks for user-generated content stored in note taking applications.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.