I never heard someone has been infected with clipboard malware using a phone Android or IOS. So I guess someone already has access to his private key and uses a script to run and automatically send funds to another wallet.
I believe OP is sending the coins to his trustwallet from a different device and that's the one which might be infected. Afaik, unlike bitcoin, you can't transfer bep coins unless the transaction gets confirmed. So, the sent coins must appear in his wallet before they get stolen if the hacker is using a bot to do so.