logo

iOS, Android Malware Steals Faces to Defeat Biometrics With AI Swaps

ID: f90d8030-14b0-5880-8b73-6263c3f1a008

STIX ID: report--f90d8030-14b0-5880-8b73-6263c3f1a008

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-15

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

GoldPickaxe is a sophisticated cross-platform banking Trojan disguised as a government service app that tricks primarily elderly victims into uploading face scans, government IDs, and phone numbers; attackers then create deepfakes to bypass biometric authentication at Southeast Asian banks, with at least one reported loss of about $40,000. Researchers link the malware to a Chinese-language group, note it evolved from a prior Trojan (GoldDigger), and recommend banks implement advanced session monitoring while advising users to avoid suspicious links and verify official apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.