TrickMo Banking Trojan Moves C2 to Telegram's TON Blockchain
A new TrickMo variant routes Android trojan traffic through The Open Network, making domain takedowns ineffective. The malware adds SSH tunneling and SOCKS5 proxy capabilities for network pivoting.