#GoldFactory
-GoldFactory campaigns hit Indonesia
-ATM jackpotting attacks rise across the US
-Google took down 80k dev accounts last year
-New Starkiller PhaaS
-New AstarionRAT
-New TrustConnect MaaS
-PromptSpy malware abuses Gemini
-New Massiv Android trojan
-PseudoSticky APT mimics an Ukrainian APT
February 20, 2026 at 10:42 AM
GoldFactory frappe l’Asie du Sud-Est avec des applis bancaires modifiées causant 11 000+ infections 📱💥. Ces cybercriminels se font passer pour des services gouvernementaux en Indonésie, Thaïlande et Vietnam. #CyberSecurity #IAÉthique #Automatisation https://kntn.ly/418cd812
GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
GoldFactory spreads modified banking apps in Southeast Asia, causing 11,000+ malware infections through government impersonation scams.
thehackernews.com
December 6, 2025 at 11:00 AM
📌 GoldFactory Distributes Malicious Banking Apps via Government Impersonation in Southeast Asia https://www.cyberhub.blog/article/16370-goldfactory-distributes-malicious-banking-apps-via-government-impersonation-in-southeast-asia
GoldFactory Distributes Malicious Banking Apps via Government Impersonation in Southeast Asia
GoldFactory, a financially motivated cybercrime group, has been targeting mobile users in Indonesia, Thailand, and Vietnam since October 2024. The group distributes Android malware through modified banking applications, with attacks impersonating government services to lure victims into installing the malicious apps. According to Group-IB, this campaign has resulted in over 11,000 infections to date. The malware compromises infected devices and exfiltrates financial data, though specific technical details about the malware's capabilities or distribution methods beyond the use of fake government lures remain undisclosed. No associated CVEs have been reported in connection with this campaign. This campaign highlights the persistent threat of mobile malware in Southeast Asia, particularly through social engineering tactics that exploit trust in government institutions. The scale of infections underscores the effectiveness of this approach and the potential for significant financial losses among affected users. From a technical perspective, the use of modified legitimate banking apps suggests a focus on evading detection while maintaining functionality to avoid immediate suspicion. However, without additional details on the malware's behavior or command-and-control infrastructure, a comprehensive technical analysis is limited. For cybersecurity professionals, this incident reinforces the importance of mobile threat detection and user education on the risks of sideloading applications or downloading software from untrusted sources. Organizations in the targeted regions should prioritize mobile security awareness and consider implementing app reputation systems to mitigate similar threats. The campaign's focus on Southeast Asia aligns with the region's growing mobile banking adoption, making it a lucrative target for financially motivated threat actors.
www.cyberhub.blog
December 5, 2025 at 8:40 AM
Threat Intelligence Report: GoldPickaxe Malware Family and GoldFactory Cybercrime Group krypt3ia.wordpress.com/2024/02/19/t...
Threat Intelligence Report: GoldPickaxe Malware Family and GoldFactory Cybercrime Group
Executive Summary In a comprehensive investigation conducted by Group-IB, a new and sophisticated cluster of banking Trojans, spearheaded by the previously unknown GoldPickaxe malware, has been uncove...
krypt3ia.wordpress.com
February 19, 2024 at 5:15 PM
GoldFactory、東南アジアで改ざんされた銀行アプリを使い11,000件以上の感染を引き起こす

GoldFactoryとして知られる金銭目的のグループに関連するサイバー犯罪者が、インドネシア、タイ、ベトナムのモバイルユーザーを標的に、政府サービスを装って新たな攻撃を仕掛けていることが確認されました。 2024年10月以降に観測された活動は、改ざんされた銀行アプリケーションを配布し、Androidマルウェアの媒介として機能させるものだと、Group-IBは水曜日に発表した技術レポートで述べています。…
GoldFactory、東南アジアで改ざんされた銀行アプリを使い11,000件以上の感染を引き起こす
GoldFactoryとして知られる金銭目的のグループに関連するサイバー犯罪者が、インドネシア、タイ、ベトナムのモバイルユーザーを標的に、政府サービスを装って新たな攻撃を仕掛けていることが確認されました。 2024年10月以降に観測された活動は、改ざんされた銀行アプリケーションを配布し、Androidマルウェアの媒介として機能させるものだと、Group-IBは水曜日に発表した技術レポートで述べています。 2023年6月にはすでに活動していたと評価されているGoldFactoryは、昨年初めに初めて注目を集めました。シンガポールに本社を置くサイバーセキュリティ企業が、GoldPickaxe、GoldDigger、GoldDiggerPlusなどのカスタムマルウェアファミリーを使い、AndroidおよびiOSデバイスの両方を標的にした脅威アクターの手口を詳述しました。 証拠によると、GoldFactoryは中国語を話すサイバー犯罪グループで、Gigabudという2023年中頃に発見された別のAndroidマルウェアと密接な関係があるとみられています。コードベースには大きな違いがあるものの、GoldDiggerとGigabudはいずれも偽装ターゲットやランディングページに類似点が見られます。 最新の攻撃波の最初の事例はタイで検出され、その後2024年末から2025年初頭にかけてベトナム、2025年中頃からはインドネシアでも脅威が現れました。 Group-IBによると、インドネシアで2,200件近い感染を引き起こした改ざん銀行アプリのユニークなサンプルを300件以上特定したとのことです。さらに調査を進めた結果、11,000件以上の感染につながったとされる3,000件超のアーティファクトも発見されました。改ざんされた銀行アプリの約63%はインドネシア市場向けです。 感染チェーンの概要としては、政府機関や信頼されたローカルブランドを装い、電話でターゲットに接触し、Zaloなどのメッセージアプリで送信したリンクをクリックさせてマルウェアをインストールさせる手口です。 Group-IBが記録した少なくとも1件の事例では、詐欺師がベトナムの公営電力会社EVNを装い、被害者に未払いの電気料金を支払うよう促し、支払わなければ即時サービス停止のリスクがあると脅しました。通話中、脅威アクターは被害者にZaloで連絡を取るよう求め、アプリのダウンロードリンクとアカウント連携のための案内を送りました。 リンクは被害者を偽のランディングページにリダイレクトし、Google Playストアのアプリリストを装っています。その結果、Gigabud、MMRat、Remoなどのリモートアクセス型トロイの木馬が展開されます。これらはGoldFactoryと同じ手口で今年初めに登場しました。これらのドロッパーは、Androidのアクセシビリティサービスを悪用してリモート操作を可能にするメインペイロードの導入につながります。 「このマルウェアは[...]元のモバイルバンキングアプリケーションをベースにしています」と研究者のAndrey Polovinkin、Sharmine Low、Ha Thi Thu Nguyen、Pavel Naumovは述べています。「アプリケーションの一部にのみ悪意のあるコードを注入することで動作し、元のアプリケーションの通常機能は維持されます。注入された悪意のあるモジュールの機能はターゲットごとに異なる場合がありますが、主に元のアプリケーションのセキュリティ機能を回避します。」 具体的には、アプリケーションのロジックにフックしてマルウェアを実行します。改ざんアプリでランタイムフックを行うために使用されるフレームワークに基づき、FriHook、SkyHook、PineHookという3種類のマルウェアファミリーが発見されています。これらの違いに関わらず、モジュールの機能は重複しており、次のことが可能です。 アクセシビリティサービスが有効なアプリ一覧を隠す 画面キャスト検出を防ぐ Androidアプリの署名を偽装する インストール元を隠す カスタムインテグリティトークンプロバイダーを実装する 被害者の口座残高を取得する SkyHookは公開されているDobbyフレームワークを使ってフックを実行し、FriHookはFridaガジェットを正規の銀行アプリに注入して利用します。PineHookはその名の通り、PineというJavaベースのフックフレームワークを使っています。 Group-IBによると、GoldFactoryが構築した悪意のあるインフラを分析した結果、Gigabudマルウェアの後継とみられる新たなAndroidマルウェア「Gigaflower」のプレリリーステストビルドも発見されました。 このマルウェアは約48種類のコマンドをサポートしており、WebRTCを使ったリアルタイムの画面・デバイスアクティビティのストリーミング、アクセシビリティサービスを悪用したキーロギングやユーザーインターフェース内容の読み取り、ジェスチャーの実行、システムアップデートやPIN入力、アカウント登録を模倣した偽画面の表示による個人情報の収集、内蔵の文字認識アルゴリズムを使った身分証画像からのデータ抽出などが可能です。 現在開発中の機能としては、ベトナムの身分証明書上のQRコードを読み取るQRコードスキャナーがあり、詳細情報の取得プロセスを簡素化することが目的とみられます。 興味深いことに、GoldFactoryは独自のiOSトロイの木馬を捨て、被害者に家族や親戚からAndroid端末を借りて手続きを続けるよう指示するという、これまでにない手法を採用しているようです。この方針転換の理由は明らかではありませんが、iOSのセキュリティ強化やアプリストアの審査厳格化が背景にあると考えられています。 「以前のキャンペーンがKYCプロセスの悪用に焦点を当てていたのに対し、最近の活動では正規の銀行アプリケーションを直接改ざんして詐欺を行っています」と研究者らは述べています。「Frida、Dobby、Pineなどの正規フレームワークを使って信頼された銀行アプリを改ざんする手法は、高度かつ低コストで、従来の検知を回避しつつサイバー犯罪者が迅速に活動を拡大できることを示しています。」 翻訳元:
blackhatnews.tokyo
December 4, 2025 at 9:40 AM

🚨 GoldFactory, the mastermind behind sophisticated banking trojans like GoldPickaxe for iOS and #Android, is now employing #deepfake tech & social engineering tactics to swipe your sensitive data.
thehackernews.com/2024/02/chin...
#cybersecurity #hacking #privacy
Chinese Hackers Using Deepfakes in Advanced Mobile Banking Malware Attacks
Chinese-speaking cybercrime group behind sophisticated banking trojans like GoldPickaxe is targeting iOS and Android users.
thehackernews.com
February 16, 2024 at 12:12 AM
ハッカーが正規のバンキングアプリに悪意あるコードを注入していることが確認される

(画像クレジット: wk1003mike / Shutterstock) Group-IB が、改ざんされたモバイルバンキングアプリを GoldFactory に関連付け 攻撃者は正規アプリを逆コンパイルし、トロイの木馬/バックドアを追加して、フィッシングメールや偽サイトを通じて拡散 高度なマルウェアファミリーによりデバイスを完全乗っ取りし、数万人規模のユーザーがバンキング詐欺の危険にさらされる…
ハッカーが正規のバンキングアプリに悪意あるコードを注入していることが確認される
(画像クレジット: wk1003mike / Shutterstock) Group-IB が、改ざんされたモバイルバンキングアプリを GoldFactory に関連付け 攻撃者は正規アプリを逆コンパイルし、トロイの木馬/バックドアを追加して、フィッシングメールや偽サイトを通じて拡散 高度なマルウェアファミリーによりデバイスを完全乗っ取りし、数万人規模のユーザーがバンキング詐欺の危険にさらされる ハッカーは、ユーザーをだまして改ざんされたモバイルバンキングアプリをダウンロードさせ、ログイン認証情報を盗み、行動を監視し、多くの場合には金融詐欺を可能にしています。 これはサイバーセキュリティ研究機関 Group-IB によるもので、同社は最近のレポートで、このグループはおそらくアジア太平洋地域で顔認証データを盗み、企業や消費者を標的としてきた GoldFactory であると述べています。 このプロセスの第一段階は、正規のバンキングアプリを逆コンパイルすることです。これにより攻撃者は、自身のコード、通常はリモートアクセス型トロイの木馬や、ある種のバックドアを追加できるようになります。その後、アプリを再コンパイルし、本物とほとんど見分けがつかないランディングページを作成します。 高度なバンキング詐欺 そこから彼らは、「標的型ソーシャルエンジニアリングキャンペーン」に乗り出し、地方自治体やさまざまなサービスプロバイダーになりすますと、研究者らは述べています。つまり攻撃者は、説得力のあるフィッシングの誘い文句を作り、人々を偽の政府機関やサービスプロバイダーのサイトに誘導し、そこで改ざんされたアプリをサイドロードさせるのです。 最悪なのは、このアプリが表面上は本来どおりに動作するため、被害者は信用してしまい、裏で何が起きているのかに気づかない点です。 「GoldFactory は SkyHook、FriHook、PineHook、Gigabud 亜種など、高度なフッキング型マルウェアファミリー一式を使用して、アプリの完全性チェックを回避し、悪意ある活動を隠蔽し、感染したデバイスを完全に制御します。これらのツールにより、攻撃者は機密データを取得し、画面上の操作を自動化し、さらには被害者のスマートフォンを遠隔で閲覧・操作することさえ可能になります」と Group-IB は説明しています。 これまでのところ焦点はアジア太平洋地域にありますが、この手法により各国への迅速な展開が可能になっているといいます。その結果、数万人のユーザーと数十の金融機関が「高インパクトのバンキング詐欺」にさらされている状況です。 インターポールの元サイバー犯罪部長である Craig Jones 氏は、最近ポッドキャスト番組「Masked Actors」の中で GoldFactory について語り、その犯行手口は「高度なバンキング詐欺だ」と述べました。 TechRadar Pro は 2024 年 2 月中旬、Gold-IB が GoldPickaxe を発見した際に、GoldFactory について初めて報じました。GoldPickaxe は生体認証データを盗み、それを使って説得力のあるディープフェイクを生成し、後にモバイルバンキングアプリへの侵入に悪用できるトロイの木馬です。 翻訳元:
blackhatnews.tokyo
December 5, 2025 at 3:06 PM
Indonesia Hit by Android Banking App-Cloning Campaign https://bit.ly/4hmKk7R by Alexander Culafi #DRGlobal
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
www.darkreading.com
September 11, 2026 at 4:45 PM
Gigabud clones your banking app into a hidden Android work profile invisible to fraud detection. https://intel.threadlinqs.com/threat/TL-2026-2444 #ThreatIntel #Gigabud #GoldDigger #GoldDiggerPlus
September 11, 2026 at 12:54 PM
インドネシアを狙うAndroidバンキング詐欺キャンペーン

GoldFactoryグループがAndroid Work Profileを悪用してGigabud Trojanを配布。同時にMantax Otaxも拡散中。銀行アプリのクローンで認証情報が狙われている。

#マルウェア #情報セキュリティ
インドネシアを狙うAndroidバンキング詐欺キャンペーン
GoldFactoryグループがAndroid Work Profileを悪用してGigabud Trojanを配布。同時にMantax Otaxも拡散中。銀行アプリのクローンで認証情報が狙われている。
www.darkreading.com
September 11, 2026 at 1:01 AM
GoldFactory explota Android Work Profile para desple

Toda la información gratis en tu bolsillo: https://t.me/EmeDotEmeNews
#EmeDotEme #Ciberseguridad #Malware
Campaña de clonación de aplicaciones bancarias Android impacta Indonesia
<p>La nación de Indonesia ha sido objeto de una campaña de ciberataques centrada en la clonación de aplicaciones bancarias móviles. Esta operación maliciosa es atribuida al grupo de amenazas GoldFacto...
www.emedoteme.es
September 11, 2026 at 2:33 AM
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection #AndroidTrojanxaBankingScam #AppCloningxaCyberFraud #Gigabud
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
 A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud detection and make stolen transactions look like they came from a clean device. Group-IB says the campaign combines Gigabud with a weaponized app-cloning tool called Vwork, which it links to the GoldFactory group.  Gigabud is not a new threat, but this latest version shows how mobile banking fraud is becoming more sophisticated. The malware reportedly uses Android’s Work Profile feature to isolate a cloned banking app from the user’s personal profile, which can break the connection between a malware alert and the later payment activity.  According to the report, Vwork exposes cloning functions through an interface that other apps on the device can call, making it easier for Gigabud to automate the attack. The trojan includes commands to provision the profile, clone a target app, and report back what was copied, while requiring a token from an external authorization server before cloning begins. The fraud chain was confirmed on devices in Indonesia, where Group-IB observed about 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026, with estimated losses of roughly $960,939. The samples were also found targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye.  To reduce risk, Group-IB recommends that banks watch for warning signs such as a work profile appearing on a phone the customer never configured, matching app markers across profiles, and suspicious accessibility access on apps that should not need it. For users, the safest habit is to install apps only from official stores and avoid suspicious links delivered through phishing sites, messengers, or social media.
dlvr.it
September 11, 2026 at 4:16 PM
Indonesia enfrenta campaña de clonación de apps bancarias en Android

Indonesia es escenario clave para un ataque de clonación de apps bancarias…

https://mentehackers.com/indonesia-enfrenta-campana-de-clonacion-de-apps-bancarias-en-android-13322757
#Ciberseguridad #Android #Tecnologia
Indonesia enfrenta campaña de clonación de apps bancarias
Indonesia es escenario clave para un ataque de clonación de apps bancarias. El grupo GoldFactory explota el feature Work Profile de Android para evadir.
mentehackers.com
September 11, 2026 at 1:26 AM
GoldFactory、オープンソースのVworkアプリクローナーを兵器化しGigabudバンキングマルウェア攻撃に悪用

GoldFactoryは、オープンソースアプリケーション「Shelter」を改造したVworkを併用することで、Androidバンキング型トロイの木馬「Gigabud」の回避能力を拡張しました。 このコンパニオンツールはAndroidの「仕事用プロファイル」による分離機能を悪用し、標的となったバンキングアプリを別の管...
GoldFactory、オープンソースのVworkアプリクローナーを兵器化しGigabudバンキングマルウェア攻撃に悪用
GoldFactoryは、オープンソースアプリケーション「Shelter」を改造したVworkを併用することで、Androidバンキング型トロイの木馬「Gigabud」の回避能力を拡張しました。 このコンパニオンツールはAndroidの「仕事用プロファイル」による分離機能を悪用し、標的となったバンキングアプリを別の管
blackhatnews.tokyo
September 9, 2026 at 11:05 AM
Zimperium found a new GoldPickaxe Trojan variant using phishing sites, obfuscation, screen scraping, and biometric theft to target mobile banking users across five countries. #GoldPickaxe #GoldFactory #China
GoldPickaxe Returns: When Your Biometric Information is as Important as Your Money
Zimperium identified a new GoldPickaxe variant targeting mobile banking users through phishing sites spoofing KuaiBo, with infections observed across five countries and 19 samples in the wild. The Trojan uses obfuscation, dynamic code loading, screen scraping, biometric theft, and C2-controlled overlays to steal credentials and exfiltrate sensitive data for GoldFactory. #GoldPickaxe #GoldFactory #KuaiBo #Zimperium #SessionInstaller #libnaLibso
www.hendryadrian.com
July 10, 2026 at 4:45 AM
GoldFactory malware alert: Over 11,000 infections from modified banking apps in Southeast Asia (ID, TH, VN). Attackers impersonate trusted services to trick users into installing dangerous apps that steal banking data.
Details ➜ sctocs.com/goldfactory-...
GoldFactory Targets Southeast Asia With Modified Banking Apps Behind 11,000 Plus Infections - SCtoCS
GoldFactory is spreading modified banking apps across Southeast Asia, leading to more than eleven thousand infections and financial risks.
sctocs.com
December 4, 2025 at 7:09 PM