:

TRICKMO BANKER MALWARE NOW USES TON BLOCKCHAIN

AI DESK1 MIN READ
MON, MAY 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new variant of TrickMo Android banking malware is leveraging The Open Network (TON) blockchain for command-and-control communications. The malware, discovered in campaigns targeting European users, introduces expanded functionality while using blockchain infrastructure to evade detection.

TrickMo, a known Android banking trojan, has evolved to incorporate TON blockchain technology for its C2 infrastructure. This shift represents an escalation in evasion tactics, as blockchain-based communications are harder to intercept and block through traditional security measures. The updated variant introduces new commands alongside its existing banking credential theft capabilities. Security researchers tracking the malware note that European users remain primary targets, with distribution occurring through established infection chains. The adoption of TON for covert communications reflects a broader trend among malware operators seeking resilience against network-level defenses. Unlike centralized C2 servers, blockchain-based infrastructure distributes command delivery across a decentralized network, complicating takedown efforts. Security firms recommend users in affected regions exercise caution with app installations and enable banking app protections. Organizations should monitor for TrickMo indicators and consider TON blockchain communication patterns as part of threat detection strategies.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.

3H AGOAI Desk

Framework's customer database was compromised in a data breach, though payment information was not exposed. The company has disclosed the incident to affected users.

4H AGODev Desk

Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.

7H AGOIndustry Desk

Flock Safety, the traffic camera company, is expanding beyond law enforcement with plans to deploy dashcams in rideshare vehicles and offer coaching services to police departments.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.