Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Striking gold: Inside the GoldDigger Android malware

7d54b0d2aa4b08244398e93a65eb3c950c5db4fc

TLP:CLEAR
Active

SHA-1 Hash

Description

GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Striking gold: Inside the GoldDigger Android malware
Pattern Type
STIX
Confidence
75%
Valid From
Aug 12, 2026 18:01
Total Sightings
0
Added
Aug 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 7d54b0d2aa4b08244398e93a65eb3c950c5db4fc

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.