# TrickMo Android Malware Evolves Again: Now Using TON Blockchain for Unstoppable Command-and-Control
Android banking malware continues to evolve at an alarming pace, with new variants introducing sophisticated evasion techniques that render traditional cybersecurity defenses increasingly ineffective. Security researchers have identified a fresh iteration of the persistent TrickMo banking trojan that leverages The Open Network (TON) blockchain for command-and-control communications, making it significantly harder for law enforcement and security teams to disrupt.
The latest variant, tracked as Trickmo.C by ThreatFabric, demonstrates how malware operators are adapting to the reality of domain takedowns and traditional infrastructure disruption. By routing commands through a decentralized peer-to-peer network rather than conventional internet servers, TrickMo's operators have created a more resilient malware operation that sidesteps the enforcement mechanisms that have worked against previous threats.
## The Threat: Banking Trojan with Expanding Arsenal
TrickMo is a sophisticated modular Android banking malware that has maintained active development and operational status since its discovery in September 2019. The malware employs a two-stage infection architecture: a host APK that functions as the loader and establishes persistence, and a runtime-downloaded APK module that contains the actual offensive functionality.
Core Capabilities:
The current variant being distributed across Europe specifically targets users in France, Italy, and Austria. ThreatFabric reports that malware samples are disguised as popular applications, including TikTok and various streaming service apps, making them deceptively difficult for users to identify as malicious.
## Background and Context: Years of Evolution
TrickMo's longevity in the threat landscape is noteworthy. First identified in 2019, the malware has not faded into obscurity like many banking trojans. Instead, it has received consistent updates and refinement over a seven-year period, indicating a well-resourced and committed criminal operation.
In October 2024 alone, Zimperium researchers analyzed 40 distinct variants of TrickMo distributed through 16 different droppers and communicating with 22 separate command-and-control infrastructures. This fragmentation suggests the operators employ a sophisticated distribution and operational security strategy, compartmentalizing their infrastructure to prevent the takedown of one component from affecting the entire operation.
The malware's persistence despite years of security research and enforcement efforts underscores a troubling reality: banking trojans targeting Android devices remain profitable and relatively low-risk for their operators. The sheer number of Android users globally—billions of devices—combined with the difficulty of patching all devices and users' inconsistent adoption of security practices creates an ideal environment for malware distribution.
## Technical Details: TON Blockchain as Operational Infrastructure
The most significant technical innovation in Trickmo.C is its adoption of The Open Network (TON) for command-and-control communications. This represents a paradigm shift in how malware operators maintain control over compromised devices.
How TON-Based C2 Works:
Rather than communicating with traditional internet servers identified by domain names and IP addresses, TrickMo.C embeds a local TON proxy on the infected Android device. This proxy routes all command-and-control traffic through the TON decentralized network, which originally developed around the Telegram ecosystem.
The technical advantages for malware operators are substantial:
| Traditional C2 Infrastructure | TON-Based C2 |
|------|------|
| Uses publicly registered domains | Uses 256-bit identifiers (.ADNL addresses) |
| IP addresses can be identified and blocked | Endpoints exist only within the overlay network |
| Domain takedowns are effective disruption | Domain takedowns are ineffective |
| Traffic is distinguishable from legitimate use | Encrypted traffic blends with other TON applications |
| Relatively straightforward to trace | Difficult to identify actual server infrastructure |
"Traditional domain takedowns are largely ineffective because the operator's endpoints do not rely on the public DNS hierarchy and instead exist as TON .adnl identities resolved inside the overlay network itself," explains ThreatFabric in their analysis. "Traffic-pattern detection at the network edge sees only TON traffic, which is encrypted and indistinguishable from any other TON-enabled application's outbound flow."
Expanded Command Set:
The latest variant introduces several new operational commands that extend the malware's utility:
These new commands suggest the operators intend to use compromised devices not only for stealing banking credentials but potentially as entry points for lateral movement within corporate networks or as nodes in larger cybercriminal infrastructure.
## Capabilities Under Development
Security researchers have identified two potentially significant capabilities that remain either incomplete or deliberately inactive:
NFC Functionality: TrickMo declares extensive Near Field Communication (NFC) permissions and reports NFC capabilities in telemetry data, yet researchers found no active NFC functionality in analyzed samples. This could indicate either work-in-progress development or infrastructure prepared for future deployment.
Pine Hooking Framework: The previously-used Pine framework for intercepting networking and Firebase operations is present but inactive, with no hooks currently installed. This suggests the operators may activate additional interception capabilities on demand or in specific campaigns.
## Implications for Android Users and Organizations
The evolution of TrickMo represents a broader trend in mobile malware development: sophistication and resilience are increasing while traditional remediation approaches become less effective.
For Individual Users:
The shift from centralized C2 infrastructure to blockchain-based command channels means that standard network-level defenses—ISP blocks, DNS filtering, firewall rules—cannot effectively interrupt the malware's communication with operators. Users cannot rely on network-edge protection.
For Organizations:
Enterprises with BYOD (Bring Your Own Device) policies or those with employees accessing financial services from personal Android devices face elevated risk. A single compromised employee device could expose corporate banking credentials, cryptocurrency holdings, or access to payment systems.
For Security Practitioners:
The traditional threat response playbook—identifying and blocking malicious infrastructure—has become significantly less effective. Researchers and defenders must shift toward behavioral detection, sandboxing analysis, and endpoint-level controls as the primary mechanism for identifying and mitigating TrickMo infections.
## Defensive Recommendations
Given the sophisticated nature of TrickMo.C and its effective evasion techniques, protection requires a layered approach:
For Individual Users:
For Organizations:
---
## HackWire Analysis
The adoption of decentralized blockchain networks like TON for malware command-and-control represents a critical inflection point in the mobile threat landscape. This is not merely an incremental technical improvement; it signals a fundamental shift in how malware operators approach operational resilience.
For years, cybersecurity strategy has relied on a simple principle: find the malware infrastructure and take it down. Law enforcement agencies and security firms have built institutional expertise around domain takedowns, ISP notifications, and infrastructure disruption. This approach worked reasonably well against malware that depended on centralized servers and registered domains.
TrickMo.C's shift to TON-based C2 invalidates this entire strategy. By leveraging an encrypted, decentralized network, the operators have created infrastructure that is fundamentally resistant to the enforcement mechanisms that have successfully disrupted previous banking trojans. This is particularly significant because TON is a legitimate cryptocurrency network—blocking all TON traffic would require cutting off legitimate users as well as malware operators, making network-level containment impractical.
The timing is also significant. We're observing this capability emerge precisely as blockchain and cryptocurrency adoption increases, making TON network traffic more common and thus easier for malware communication to blend in. Early adopters of this technique gain asymmetric advantage; as more legitimate applications use TON and similar networks, malware operators will find their C2 traffic increasingly indistinguishable from ordinary network activity.
Perhaps most concerning is what this innovation enables: it lowers the barrier for other malware operators to adopt similar techniques. Once the proof-of-concept is established and documented, copycat malware developers will rapidly implement blockchain-based C2 in their own tools. We should expect to see this pattern spreading across Android malware variants, Windows malware, and IoT botnet families within the next 12-18 months.
Defenders must adapt by shifting investment away from infrastructure takedown as a primary mitigation and toward behavioral detection, endpoint hardening, and financial account monitoring as the critical layers. Organizations cannot assume that traditional network controls will prevent compromised devices from communicating with attackers; they must assume compromise will occur and focus on limiting the damage.
The security community's response to this evolution will largely determine whether mobile malware continues to grow as a significant financial threat or whether defensive innovations can keep pace with operator capabilities.
— HackWire Editorial
---
## Related Coverage