TrickMo is no longer easy to disrupt by blocking domains or taking down servers. Its latest Android banker variant routes command-and-control through TON and an embedded local proxy on the infected device, which makes the operator harder to identify, block, or shut down with standard network controls.
ThreatFabric says it has tracked this TrickMo.C variant since January. The malware is being pushed as fake TikTok or streaming apps and is targeting banking and cryptocurrency wallet users in France, Italy, and Austria. TON traffic is encrypted and uses .ADNL identities instead of normal domains, so edge monitoring sees only generic TON traffic.
That shifts the defender problem from infrastructure takedown to endpoint and account abuse on unmanaged Android devices. The immediate risk is credential theft from banking and crypto apps, and the C2 channel can persist even when known hosting is blocked.