GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the Asia-Pacific region, specifically Vietnam and Thailand. They utilize social engineering to deliver malware to victims' devices and have close connections to the Gigabud malware family. GoldFactory's Trojans, such as GoldPickaxe and GoldDigger, employ tactics like smishing, phishing, and fake login screens to compromise victims' phones and steal sensitive information. Their evolving malware suite demonstrates a high level of operational maturity and ingenuity, requiring a proactive and multi-faceted cybersecurity approach to detect and mitigate their threats.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GoldFactory is a sophisticated mobile banking malware threat group targeting primarily Asia-Pacific regions, including Vietnam and Thailand. They employ social engineering tactics to distribute malware through smishing and phishing, compromising devices to steal sensitive financial information. Their strategic targeting of key sectors in emerging economies poses significant risks to financial stability and organizational security.
Goals & Targeting
GoldFactory's primary objectives appear to be financial gain through the theft of sensitive information, with a focus on sectors such as financial services that hold valuable data. They target countries like Indonesia, Peru, Philippines, South Africa, and Thailand, potentially due to their mobile-first banking environments and varying levels of cybersecurity maturity. This strategic targeting allows them to maximize their attack success rates while minimizing detection risks.
Enhanced Description
GoldFactory is a threat actor group known for developing advanced mobile banking malware that targets individuals across the Asia-Pacific region, particularly in Vietnam and Thailand. They utilize social engineering techniques such as smishing, phishing campaigns, and fake login screens to deceive victims into installing their malicious software, leading to unauthorized access of sensitive information including financial credentials. The group's connection to the Gigabud malware family and their use of Trojans like GoldPickaxe and GoldDigger highlight a high level of technical sophistication. Their ability to adapt and evolve their attack methods underscores the need for robust cybersecurity measures to counteract these threats.
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GoldFactory has been observed conducting long-term campaigns across the Asia-Pacific region, leveraging diverse tactics to evade detection. Their operations typically involve targeting financial institutions and mobile banking users through sophisticated phishing attacks that exploit human error. The group's malware evolves frequently, indicating a capacity for rapid adaptability and innovation in attack techniques, making them challenging to counter.
IOC Patterns
Recommended Actions
Suggested Tags
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
57
IOCs
0
Observed Data
0
Tactics