Security specialists have discovered a new variant of the TrickMo banking Trojan, which has compromised approximately 13,000 Android devices.
Zimperium, building on earlier research by Cleafy, indicates that the malware spreads primarily through phishing schemes and social engineering tactics, often disguising itself as genuine banking or utility applications.
This updated version of TrickMo poses a significant threat as it can hide its code from detection and capture device unlock patterns or PINs. Additionally, it has the ability to intercept login information, one-time passwords, access private files, grant permissions, record screens, and even remotely control devices.
These features contribute to its potential for serious threats, including identity theft.
Experts note that while TrickMo continues to function as a typical Android banking Trojan, the data it gathers could enable attackers to exploit victims on multiple fronts. This malware is linked to the TrickBot group, a criminal syndicate believed to operate out of Russia.
Zimperium’s research highlights that over 13,000 IP addresses have been affected, with victims predominantly found in Canada, the UAE, Turkey, and Germany, demonstrating the extensive impact of this malware campaign.
A U.S. woman recently became the victim of a major cryptocurrency scam, losing millions of dollars after falling for a well-crafted deception.
The first quarter of 2025 has been marked by a significant surge in crypto hacks, with losses totaling over $1.63 billion.
In the past two weeks, Coinbase users may have fallen victim to phishing schemes resulting in an estimated $46 million in losses, as malicious actors continue to exploit the growing interest in cryptocurrency.
A South Korean court recently handed down prison sentences to three individuals involved in a cryptocurrency investment scam that defrauded investors of approximately $460,000.