TrickMo Variant Routes Android Trojan Traffic Through TON
2026-05-11T20:52:20Z•05b3a9bfc888ec00d9a217bd3c64b94d5b88fb3cda17bd5ad0d5b15f2b64fa4c
AI-developed zero-dayBeagle backdoorCISACanvas extortionClickFixCline KanbanCloudZ RATDirty FragDonutLoaderLLM misuseLinux kernelNCSCPheno pluginPowerShell stealerShinyHuntersThe Open Network (TON)TrickMoVercel phishingVidarWebSocket hijackZara data breachcritical infrastructure attackfake Claudeinfostealer','ransomware','supply-chainphishing
What happened
This feed highlights multiple active, high-impact threats and vulnerability trends: ThreatFabric discovered a new TrickMo Android banking‑trojan variant routing C2 traffic via The Open Network (TON); two new high‑severity Linux kernel flaws (chainable as “Dirty Frag”) prompted rushed patches; and several fake Claude/AI‑themed distribution sites/installers are spreading PowerShell stealers, DonutLoader and a Beagle backdoor via DLL sideloading. Researchers also report criminals using LLMs to develop zero‑day exploits, a rise in phishing abusing Vercel and fake compliance emails (targeting tens‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 05b3a9bfc888ec00d9a217bd3c64b94d5b88fb3cda17bd5ad0d5b15f2b64fa4c
- Enrichment time
- 2026-05-11T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.