TrickMo is an Android banking trojan associated with campaigns linked to TrickBot-related fraud operations and later observed as an actively evolving mobile threat targeting banking, fintech, cryptocurrency wallet, email, commerce, and authentication applications. First identified in 2019, it was used to bypass mobile-based transaction authentication and one-time passcode protections, particularly in banking fraud workflows involving infected desktop systems and social-engineering prompts to install a malicious Android application.
TrickMo is designed for device takeover and fraud enablement rather than simple SMS theft alone. It abuses Android Accessibility Services to automate permission grants, interact with system dialogs, monitor targeted applications, scrape on-screen content, and drive user-interface actions without the victim’s knowledge. More recent variants use overlay-based credential theft through WebView-loaded phishing content and support extensive remote command functionality. Reported capabilities include intercepting and deleting SMS messages, collecting installed application lists, gathering device and network configuration information, stealing photos and other local data, reading call logs, sending SMS, setting itself as the default SMS application, downloading additional modules, updating itself, changing its icon, and manipulating device settings. Earlier variants also used screen-recording functionality, while later variants shifted toward accessibility-event monitoring and overlay delivery.
For persistence and event-triggered execution, TrickMo registers Android broadcast receivers including SCREEN_ON and SMS_DELIVER so it can react when the device is unlocked or an SMS arrives. It has also been reported to resist removal and to use standard application-layer network communications, including JSON over unencrypted HTTP, for command and control and data exfiltration.
Distribution has included delivery through TrickBot-facilitated web injects shown during online banking sessions on compromised Windows systems, where victims were lured into installing a fake security application on Android. More recent activity shows continued development of the family and expanded targeting of financial and authentication ecosystems, reflecting a broader shift toward full on-device session manipulation and fraud operations that can undermine traditional multi-factor authentication controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is also capable of gaining persistence on infected Android devices by registering a receiver that will listen for android.intent.action.SCREEN_ON and android.provider.Telephony.SMS_DELIVER broadcasts to restart itself after a reboot when the screen turns on or an SMS is received.
The malware is also capable of gaining persistence on infected Android devices by registering a receiver that will listen for android.intent.action.SCREEN_ON and android.provider.Telephony.SMS_DELIVER broadcasts to restart itself after a reboot when the screen turns on or an SMS is received.
Dropper apps containing the malware masquerade as adult versions of TikTok, whereas the actual malware impersonates Google Play Services
This allows the Android Trojan to delete SMS messages it forwards to its masters so that the victims are never aware that their devices received a text message with a 2FA code from their banks.
it was recently updated, in January 2020, with code that checks if the malware is running on a rooted device or an emulator.
The host APK acts primarily as a launcher and persistence layer, while the offensive functionality is delivered separately through the dynamically loaded APK with package name " dex.module " fetched from operator infrastructure at runtime and injected into the running process.
Once installed on Android devices, the malware abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, and manipulate app sessions directly on the device.
Keylogging that captures typed text and field metadata correlated with the foreground package
After the infection, a webinject is deployed by Dreambot on the victim browsers and when that victims logs into the online banking service, credentials are intercepted to be later reused by the carder.
The Android app dubbed TrickMo ... is using a malicious Android application they developed to bypass two-factor authentication (2FA) protection used by various banks after stealing transaction authentication numbers.
dnsLookup deliberately uses the platform resolver rather than the bot's DoH path, so the operator learns what the device's network sees for a given name.
Monokle checks if the device is connected via Wi-Fi or mobile data; Pegasus for Android checks if the device is on Wi-Fi, a cellular network, and is roaming; TianySpy can check to see if Wi‑Fi is enabled; TERRACOTTA can check if the active network connection is metered; TrickMo can collect device network configuration information such as IMSI, IMEI, and Wi‑Fi connection state.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
Once installed on Android devices, the malware abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, and manipulate app sessions directly on the device.
Keylogging that captures typed text and field metadata correlated with the foreground package
The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy.
AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; BRATA can use both HTTP and WebSockets to communicate with the C2 server; LightSpy has used both HTTPS and Websockets to communicate with the C2.
An on-device SOCKS5 proxy with user-and-password authentication turns the infected handset into a per-request-routed network exit node.
The host APK acts primarily as a launcher and persistence layer, while the offensive functionality is delivered separately through the dynamically loaded APK with package name " dex.module " fetched from operator infrastructure at runtime and injected into the running process.
Once installed on Android devices, the malware abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, and manipulate app sessions directly on the device.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware that abuses accessibility services and remote-control functions to capture credentials, intercept one-time passcodes, manipulate app sessions, and enable device takeover within legitimate financial and authentication apps.
Android device takeover malware active since late 2019 that abuses accessibility services to hijack OTPs, phish for credentials, log keystrokes, record and stream screens, intercept SMS messages, and provide remote control of infected devices. The latest variant uses TON-based C2 and adds reconnaissance, SSH tunnelling, and SOCKS5 proxying to turn compromised phones into programmable network pivots and traffic-exit nodes.
Android banking malware that abuses accessibility services to take over devices, steal credentials, log keystrokes, intercept and suppress SMS and OTP notifications, record screens, enable live remote interaction, and route malicious traffic through the victim device using SSH tunnelling and an authenticated SOCKS5 proxy. The new variant also uses TON-based C2 and loads a runtime module named dex.module for remote-control functionality.
An Android banking trojan with modular architecture that supports persistence, fake banking overlays, keystroke capture, SMS interception, notification monitoring, screen recording, remote device control, and newer network-operations features including DNS lookups, ping, traceroute, HTTP requests, SSH tunneling, and SOCKS5 proxying via infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.