Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GoldFactory

Description

GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the Asia-Pacific region, specifically Vietnam and Thailand. They utilize social engineering to deliver malware to victims' devices and have close connections to the Gigabud malware family. GoldFactory's Trojans, such as GoldPickaxe and GoldDigger, employ tactics like smishing, phishing, and fake login screens to compromise victims' phones and steal sensitive information. Their evolving malware suite demonstrates a high level of operational maturity and ingenuity, requiring a proactive and multi-faceted cybersecurity approach to detect and mitigate their threats.

Goals & Targeting

Targeted Sectors

Government
Financial services
Energy
Transportation
Healthcare

Targeted Countries / Regions

Indonesia
Peru
Philippines
South Africa
Thailand

AI Analysis

· 1 week ago

Executive Summary

GoldFactory is a sophisticated mobile banking malware threat group targeting primarily Asia-Pacific regions, including Vietnam and Thailand. They employ social engineering tactics to distribute malware through smishing and phishing, compromising devices to steal sensitive financial information. Their strategic targeting of key sectors in emerging economies poses significant risks to financial stability and organizational security.

Goals & Targeting

GoldFactory's primary objectives appear to be financial gain through the theft of sensitive information, with a focus on sectors such as financial services that hold valuable data. They target countries like Indonesia, Peru, Philippines, South Africa, and Thailand, potentially due to their mobile-first banking environments and varying levels of cybersecurity maturity. This strategic targeting allows them to maximize their attack success rates while minimizing detection risks.

Enhanced Description

GoldFactory is a threat actor group known for developing advanced mobile banking malware that targets individuals across the Asia-Pacific region, particularly in Vietnam and Thailand. They utilize social engineering techniques such as smishing, phishing campaigns, and fake login screens to deceive victims into installing their malicious software, leading to unauthorized access of sensitive information including financial credentials. The group's connection to the Gigabud malware family and their use of Trojans like GoldPickaxe and GoldDigger highlight a high level of technical sophistication. Their ability to adapt and evolve their attack methods underscores the need for robust cybersecurity measures to counteract these threats.

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access

ATT&CK Techniques

T1059
T1663
T1584
T1078

Software / Tooling

GoldPickaxe
GoldDigger
Gigabud Malware Family

Campaigns & Victims

GoldFactory has been observed conducting long-term campaigns across the Asia-Pacific region, leveraging diverse tactics to evade detection. Their operations typically involve targeting financial institutions and mobile banking users through sophisticated phishing attacks that exploit human error. The group's malware evolves frequently, indicating a capacity for rapid adaptability and innovation in attack techniques, making them challenging to counter.

IOC Patterns

  • Spear-phishing emails with malicious links or QR codes
  • Fake login pages mimicking legitimate banking services
  • Command-and-control domains resembling genuine financial institutions
  • Distribution of mobile malware via SMS or email attachments

Recommended Actions

  • Implement advanced mobile device management solutions to detect and block suspicious apps
  • Educate employees about social engineering tactics through regular training programs
  • Monitor network traffic for signs of command-and-control communication patterns
  • Use threat intelligence feeds specifically tailored to mobile banking malware threats
  • Regularly update and patch mobile devices and financial applications

Suggested Tags

APT
malware
banking
Asia-Pacific
espionage

Intel Summary

0

Techniques

0

Tools

0

Campaigns

57

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Critical Infrastructure
Phishing
APT
malware
banking
Asia-Pacific
espionage

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.