logo

Face Off: Group-IB identifies first iOS trojan stealing facial recognition data

ID: 1aa1b0d8-d00e-51d5-9b7a-3082931f3069

STIX ID: report--1aa1b0d8-d00e-51d5-9b7a-3082931f3069

Feed Name: Group-IB Blog

Threat Score
80/100

Date Published: 2024-02-15

Date Updated: 2026-04-27

...
...

Group-IB discovered and analyzed a sophisticated mobile banking malware cluster operated by a group named GoldFactory that targets users in Vietnam and Thailand; the families (GoldDigger, GoldDiggerPlus, GoldKefu, GoldPickaxe) steal banking credentials, SMS, ID documents and facial biometric data (used for AI-driven deepfakes), use social engineering (smishing, fake sites, TestFlight, and fraudulent MDM profiles) to distribute malware, and employ proxies/FRP, websockets and cloud buckets for control and exfiltration—posing a high-risk threat to financial customers and institutions in the APAC region.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.