Chinese Hackers Using Deepfakes in Advanced Mobile Banking Malware Attacks
ID: 353ad26c-ce58-5390-94f5-1cd719da1736
STIX ID: report--353ad26c-ce58-5390-94f5-1cd719da1736
Feed Name: The Hacker News
GoldFactory, a Chinese-speaking cybercrime group active since mid-2023, operates a suite of mobile banking malware — including GoldPickaxe (iOS/Android), GoldDigger, GoldDiggerPlus, and GoldKefu — that target victims in Thailand and Vietnam via smishing, phishing, counterfeit app sites, and TestFlight/MDM installs. The malware harvests identity documents and photos, captures facial recognition data for deepfake-assisted fraud, intercepts SMS, proxies traffic, abuses Android accessibility services and overlays to steal credentials, and uses features like Agora SDK to simulate bank support calls; researchers report high operational maturity and rapid toolset evolution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
