Hook for Gold: Inside GoldFactory’s Сampaign That Turns Apps Into Goldmines
ID: cda3466f-6dac-56ab-b63e-4bc3cc5ac794
STIX ID: report--cda3466f-6dac-56ab-b63e-4bc3cc5ac794
Feed Name: Group-IB Blog
This Group-IB report describes the GoldFactory criminal group's evolving mobile banking campaign across APAC, detailing how attackers sideload modified legitimate banking apps (FriHook, SkyHook, PineHook, Gigaflower) after initial compromise via droppers (Gigabud, Remo, MMRat) and social-engineering (smishing/vishing). The analysis covers technical methods (Frida/Dobby/Pine hooking, WebRTC streaming, OCR/QR harvesting of ID cards), documented IOCs (SHA256s, domains, IPs), infection telemetry showing thousands of victims, and defensive recommendations for banks and end users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
