logo

Chinese Hackers Using Deepfakes in Advanced Mobile Banking Malware Attacks

ID: 353ad26c-ce58-5390-94f5-1cd719da1736

STIX ID: report--353ad26c-ce58-5390-94f5-1cd719da1736

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

GoldFactory, a Chinese-speaking cybercrime group active since mid-2023, operates a suite of mobile banking malware — including GoldPickaxe (iOS/Android), GoldDigger, GoldDiggerPlus, and GoldKefu — that target victims in Thailand and Vietnam via smishing, phishing, counterfeit app sites, and TestFlight/MDM installs. The malware harvests identity documents and photos, captures facial recognition data for deepfake-assisted fraud, intercepts SMS, proxies traffic, abuses Android accessibility services and overlays to steal credentials, and uses features like Agora SDK to simulate bank support calls; researchers report high operational maturity and rapid toolset evolution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.