logo

New ‘Gold Pickaxe’ Android, iOS malware steals your face for fraud

ID: 3c13476a-88c1-54ea-9327-19930988371c

STIX ID: report--3c13476a-88c1-54ea-9327-19930988371c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Group-IB reports a multi-platform mobile trojan named GoldPickaxe, used by the GoldFactory group since mid-2023 to socially engineer victims (primarily in Thailand and Vietnam) into installing fake government apps via LINE phishing/smishing, TestFlight links, or malicious MDM profiles; the trojan captures face videos and ID images, intercepts SMS, exfiltrates photos, proxies traffic, and exposes commands for remote control, enabling suspected biometric-enabled banking fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.