logo

Hook for Gold: Inside GoldFactory’s Сampaign That Turns Apps Into Goldmines

ID: cda3466f-6dac-56ab-b63e-4bc3cc5ac794

STIX ID: report--cda3466f-6dac-56ab-b63e-4bc3cc5ac794

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2025-12-03

Date Updated: 2026-04-28

...
...

This Group-IB report describes the GoldFactory criminal group's evolving mobile banking campaign across APAC, detailing how attackers sideload modified legitimate banking apps (FriHook, SkyHook, PineHook, Gigaflower) after initial compromise via droppers (Gigabud, Remo, MMRat) and social-engineering (smishing/vishing). The analysis covers technical methods (Frida/Dobby/Pine hooking, WebRTC streaming, OCR/QR harvesting of ID cards), documented IOCs (SHA256s, domains, IPs), infection telemetry showing thousands of victims, and defensive recommendations for banks and end users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.