Face Off: Group-IB identifies first iOS trojan stealing facial recognition data
ID: 1aa1b0d8-d00e-51d5-9b7a-3082931f3069
STIX ID: report--1aa1b0d8-d00e-51d5-9b7a-3082931f3069
Feed Name: Group-IB Blog
Group-IB discovered and analyzed a sophisticated mobile banking malware cluster operated by a group named GoldFactory that targets users in Vietnam and Thailand; the families (GoldDigger, GoldDiggerPlus, GoldKefu, GoldPickaxe) steal banking credentials, SMS, ID documents and facial biometric data (used for AI-driven deepfakes), use social engineering (smishing, fake sites, TestFlight, and fraudulent MDM profiles) to distribute malware, and employ proxies/FRP, websockets and cloud buckets for control and exfiltration—posing a high-risk threat to financial customers and institutions in the APAC region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
