TF-MAL-apk.trickmo
📛 Threat Title
Malware family: TrickMo
Description
ThreatFox malware family `apk.trickmo`. Printable name: TrickMo.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.trickmo
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.trickmo
IOC database
- Type
- domain
- Value
apk.trickmo- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.trickmo
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.trickmo
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
Threat actors are rewriting the rulebook on mobile malware . Instead of simply building entirely new malicious tools, hackers are drastically re-engineering older threats to be virtually undetectable. A highly stealthy new variant of the TrickMo Android banking trojan has emerged, actively targeting banking, fintech, and crypto wallet users across France, Italy, and Austria. By completely ...
-
web:cybersecuritynews.com
A dangerous Android banking malware known as TrickMo has resurfaced with a powerful new variant, and this time it is more stealthy, more capable, and harder to stop than ever before. The threat is actively targeting users of banking apps, digital wallets, and authenticator applications across Europe, putting financial data and account access at serious risk. The malware spreads through fake ...
-
web:dailysecurityreview.com
Table of Contents ThreatFabric researchers have identified a new TrickMo Android banking trojan variant that routes command-and-control communications through The Open Network (TON) blockchain, marking the first documented deployment of decentralized blockchain infrastructure as a C2 channel in a major mobile banking malware family .
-
web:gbhackers.com
TrickMo , the Android banking malware , has resurfaced with a significantly redesigned architecture, targeting banking, fintech, wallet, and authenticator applications.
-
web:netcrook.com
A resurfaced Android malware family is shifting from noisy credential theft toward a more durable device-takeover model aimed at banking, fintech, wallet, and authenticator apps.
-
web:thehackernews.com
A new TrickMo Android banking trojan variant uses TON blockchain infrastructure for stealthy command-and-control communications.
-
web:www.cleafy.com
Explore Cleafy's analysis of a newly discovered TrickMo variant, revealing enhanced malware capabilities and critical endpoints used for storing stolen credentials and data from victims. Here is the latest threat analyst report.
-
web:www.firstpost.com
The TrickMo virus was first identified and tracked between January and February 2026, and was regarded at the time as an Android banking trojan family virus under active monitoring. While occurrences of its attacks had died down over the past few months, a new version of the virus has recently resurfaced and begun disrupting established financial systems. The platform that forms the basis of ...
-
web:www.infosecurity-magazine.com
A new variant of the TrickMo Android banking trojan has moved its primary command-and-control (C2) transport onto The Open Network (TON) Blockchain, routing communications through the decentralized overlay's .adnl identities to make traditional domain takedowns largely ineffective.
-
web:www.threatfabric.com
Perseus is a new Device Takeover (DTO) malware family that specifically looks for user-generated content stored in note taking applications.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.