TrickMo

MITRE ATT&CK: S0427 View on attack.mitre.org

Aliases: TrickMo

Malware type
trojan
Family
Malware family
Operating systems
android
Related IoCs
95 (62 malicious)
Last IoC activity
2026-08-13 22:41:46
Profile updated
2026-07-07 14:10:08

Targeted industries: financial-services

Targeted regions: country_code:de

Context

TrickMo a 2FA bypass mobile banking trojan, most likely being distributed by TrickBot. TrickMo has been primarily targeting users located in Germany. TrickMo is designed to steal transaction authorization numbers (TANs), which are typically used as one-time passwords.

Recent IoC activity

62 malicious indicators in Maltiverse are attributed to TrickMo (S0427). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 4284e6bbc2fc274d8b0a1f37f91408efc0404e4cae0ba28abc4d583bc59af6bd.apk 2026-08-13 2
file sample AdGuard.apk 2026-05-27 1
hostname skyfrostweb.cn.com 2026-04-19 1
hostname heyclodere.at 2026-04-07 1
file sample payload.apk 2026-03-14 1
file sample TikTok18plus.apk 2026-03-14 1
hostname b-need-for-speed.online 2026-03-03 1
file sample TrickMo.apk 2026-02-27 2
file sample 53e3b161de04d71adfe6b2757cac9c349cd4ff4b49fc9de5371d4dc3f6b21ade 2026-02-27 1
hostname starnow.cn.com 2026-02-09 1
hostname traktortany.org 2026-01-30 1
URL http://193.143.1.138/negxsh3dy1mdkqphuc 2026-01-24 1
file sample cd93e6064dfdec9bf66e88aa413cb693 2026-01-15 1
URL http://havebeprotredo.at/243uwuyki 2026-01-03 1
URL http://mobiportal.at/itezlthrf5m 2025-12-31 1
file sample 57.apk 2025-12-01 1
file sample f9.apk 2025-12-01 1
URL http://shoesdiscountmee.info/bsq808t 2025-11-08 1
file sample 7b.apk 2025-10-17 1
file sample 9a.apk 2025-10-17 1

Malware & tools used

  • Broadcast Receivers (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Device Lockout (attack-pattern)
  • Web Protocols (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • SMS Messages (attack-pattern)
  • Software Discovery (attack-pattern)
  • Uninstall Malicious Application (attack-pattern)
  • Input Injection (attack-pattern)
  • Out of Band Data (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • SMS Control (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Checks (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Reports & references

  • medium.com — Analysis Of Malicious Mobile Applications Impersonating Popular Polish Apps Olx Allegro Iko 7Dab879A320D (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Trickmo (report)
  • zimperium.com — Expanding The Investigation Deep Dive Into Latest Trickmo Samples (report)
  • cyble.com — Trickmos Return Banking Trojan Resurgence With New Features (report)
  • securityintelligence.com — Trickbot Pushing A 2Fa Bypass App To Bank Customers In Germany (report)
  • cleafy.com — A New Trickmo Saga From Banking Trojan To Victims Data Leak (report)
  • MITRE ATT&CK — S0427 (report)

External references