TrickMo Variant Routes Android Trojan Traffic Through TON

2026-05-11T20:52:20Z05b3a9bfc888ec00d9a217bd3c64b94d5b88fb3cda17bd5ad0d5b15f2b64fa4c
AI-developed zero-dayBeagle backdoorCISACanvas extortionClickFixCline KanbanCloudZ RATDirty FragDonutLoaderLLM misuseLinux kernelNCSCPheno pluginPowerShell stealerShinyHuntersThe Open Network (TON)TrickMoVercel phishingVidarWebSocket hijackZara data breachcritical infrastructure attackfake Claudeinfostealer','ransomware','supply-chainphishing

What happened

This feed highlights multiple active, high-impact threats and vulnerability trends: ThreatFabric discovered a new TrickMo Android banking‑trojan variant routing C2 traffic via The Open Network (TON); two new high‑severity Linux kernel flaws (chainable as “Dirty Frag”) prompted rushed patches; and several fake Claude/AI‑themed distribution sites/installers are spreading PowerShell stealers, DonutLoader and a Beagle backdoor via DLL sideloading. Researchers also report criminals using LLMs to develop zero‑day exploits, a rise in phishing abusing Vercel and fake compliance emails (targeting tens‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
05b3a9bfc888ec00d9a217bd3c64b94d5b88fb3cda17bd5ad0d5b15f2b64fa4c
Enrichment time
2026-05-11T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TrickMo Variant Routes Android Trojan Traffic Through TON · Baitaphish