TrickMo Returns: The Android Trojan That’s Out to Steal Your Passwords and Ruin Your Day

Cybersecurity researchers have discovered a new TrickMo variant targeting Android devices. Packed with advanced evasion techniques and fake login screens, this banking trojan steals credentials and two-factor authentication codes. Masquerading as Google Chrome, it exploits accessibility services to control devices, intercept messages, and perform on-device…

Hot Take:

Just when you thought it was safe to check your bank balance on your phone, TrickMo swoops in like a digital ninja, armed with a bag of sneaky tricks that would make even Houdini jealous. Move over, pickpockets; it’s the era of the pixelated pilferer!

Key Points:

  • TrickMo, a notorious Android banking trojan, has evolved with new anti-analysis features.
  • The malware uses a dropper app disguised as Google Chrome to install itself.
  • It exploits Android’s accessibility services to gain extensive control over infected devices.
  • A misconfigured C2 server exposed 12 GB of sensitive data, including credentials and photos.
  • Google is working to mitigate the threat by enhancing security around sideloading apps.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here