02 GoldFactory

GoldFactory

Region
Asia-Pacific
Industries
Banking
First seen
May 2024
Cybercrime
Emerging group signalling a possible evolution in AI-driven attacks, with the potential to disrupt the financial systems of targeted countries
Heritage
Group-IB uncovered the malware GoldDigger in June 2023, part of the GoldPickaxe family
Categorizations
Mobile banking malware
About

Currently, there’s limited public information on this Masked Actors group. However, in May 2024, we uncovered the first iOS trojan, dubbed GoldPickaxe.iOS. Part of a sophisticated suite of mobile banking malware, this trojan harvests facial recognition data for unauthorized access to bank accounts using deep fakes — introducing a new monetary theft technique previously unseen. This threat cluster has been attributed to a single actor, codenamed: GoldFactory.

Victims

Tend to be finance companies, predominantly in the Asia-Pacific (APAC) region, with evidence suggesting a strong focus on Vietnam and Thailand firms.

What we know about GoldFactory members

There are indications GoldFactory will expand its operations beyond its two target countries.

Motivations
Financial gain via AI-enabled iOS and Android trojans.
Top 10 Masked Actors for 2025
RansomHub
#1
GoldFactory
#2
Lazarus
#3
DragonForce
#4
Oilrig
#5
MuddyWater
#6
Brain Cipher
#7
Boolka
#8
Ajina
#9
Team TNT
#10