TrickMo
MITRE ATT&CK: S0427 View on attack.mitre.org
Aliases: TrickMo
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 95 (62 malicious)
- Last IoC activity
- 2026-08-13 22:41:46
- Profile updated
- 2026-07-07 14:10:08
Targeted industries: financial-services
Targeted regions: country_code:de
Context
TrickMo a 2FA bypass mobile banking trojan, most likely being distributed by TrickBot. TrickMo has been primarily targeting users located in Germany. TrickMo is designed to steal transaction authorization numbers (TANs), which are typically used as one-time passwords.
Recent IoC activity
62 malicious indicators in Maltiverse are attributed to TrickMo (S0427). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 4284e6bbc2fc274d8b0a1f37f91408efc0404e4cae0ba28abc4d583bc59af6bd.apk | 2026-08-13 | 2 |
| file sample | AdGuard.apk | 2026-05-27 | 1 |
| hostname | skyfrostweb.cn.com | 2026-04-19 | 1 |
| hostname | heyclodere.at | 2026-04-07 | 1 |
| file sample | payload.apk | 2026-03-14 | 1 |
| file sample | TikTok18plus.apk | 2026-03-14 | 1 |
| hostname | b-need-for-speed.online | 2026-03-03 | 1 |
| file sample | TrickMo.apk | 2026-02-27 | 2 |
| file sample | 53e3b161de04d71adfe6b2757cac9c349cd4ff4b49fc9de5371d4dc3f6b21ade | 2026-02-27 | 1 |
| hostname | starnow.cn.com | 2026-02-09 | 1 |
| hostname | traktortany.org | 2026-01-30 | 1 |
| URL | http://193.143.1.138/negxsh3dy1mdkqphuc | 2026-01-24 | 1 |
| file sample | cd93e6064dfdec9bf66e88aa413cb693 | 2026-01-15 | 1 |
| URL | http://havebeprotredo.at/243uwuyki | 2026-01-03 | 1 |
| URL | http://mobiportal.at/itezlthrf5m | 2025-12-31 | 1 |
| file sample | 57.apk | 2025-12-01 | 1 |
| file sample | f9.apk | 2025-12-01 | 1 |
| URL | http://shoesdiscountmee.info/bsq808t | 2025-11-08 | 1 |
| file sample | 7b.apk | 2025-10-17 | 1 |
| file sample | 9a.apk | 2025-10-17 | 1 |
Malware & tools used
- Broadcast Receivers (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Device Lockout (attack-pattern)
- Web Protocols (attack-pattern)
- Wi-Fi Discovery (attack-pattern)
- SMS Messages (attack-pattern)
- Software Discovery (attack-pattern)
- Uninstall Malicious Application (attack-pattern)
- Input Injection (attack-pattern)
- Out of Band Data (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- SMS Control (attack-pattern)
- Data from Local System (attack-pattern)
- System Checks (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
Reports & references
- medium.com — Analysis Of Malicious Mobile Applications Impersonating Popular Polish Apps Olx Allegro Iko 7Dab879A320D (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Trickmo (report)
- zimperium.com — Expanding The Investigation Deep Dive Into Latest Trickmo Samples (report)
- cyble.com — Trickmos Return Banking Trojan Resurgence With New Features (report)
- securityintelligence.com — Trickbot Pushing A 2Fa Bypass App To Bank Customers In Germany (report)
- cleafy.com — A New Trickmo Saga From Banking Trojan To Victims Data Leak (report)
- MITRE ATT&CK — S0427 (report)