GoldFactory
GoldFactory is a financially motivated Chinese-speaking cybercrime group targeting mobile users in Southeast Asia, particularly in Indonesia, Thailand, and Vietnam. The group has been observed since at least October 2024 impersonating government services and other trusted entities to distribute modified banking applications and Android malware. Reported lures include impersonation of government services and Vietnam's public power company EVN, with victims contacted via phone calls and messaging apps such as Zalo and redirected to fake Google Play landing pages. Group-IB linked GoldFactory to campaigns using custom malware families including GoldPickaxe, GoldDigger, and GoldDiggerPlus, and connected the group to the Gigabud Android malware. Recent campaigns have delivered Android malware and remote access trojans including Gigabud, MMRat, and Remo. GoldFactory has also developed a newer Android malware variant, Gigaflower, identified through the group's infrastructure. The group's operations focus on mobile banking fraud. Their malware abuses Android accessibility services for remote control and injects malicious code into legitimate banking apps while preserving normal app functionality. Reported runtime-hooking malware families used in modified apps include FriHook, SkyHook, and PineHook, which leverage the Frida gadget, Dobby, and Pine frameworks respectively. These capabilities are used to bypass security features, hide malicious activity, prevent screencast detection, spoof app signatures, hide installation sources, implement custom integrity tokens, and obtain account balances. Gigaflower reportedly supports 48 commands, including real-time device streaming, keylogging, UI reading, gesture automation, fake screen serving, and extraction of data from ID card images; a QR code scanner for Vietnamese identity cards was under development. According to the provided reporting, GoldFactory's latest wave was first detected in Thailand and then spread to Vietnam and Indonesia. Group-IB identified over 300 unique samples of modified banking apps and more than 3,000 related artifacts, resulting in at least 11,000 infections, with the majority of altered apps targeting the Indonesian market. The group previously used iOS malware in earlier campaigns tied to KYC process abuse, but has reportedly shifted away from iOS and now instructs victims to use Android devices, likely due to stricter iOS security.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- finance
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated mobile-focused cybercrime group distributing modified banking apps and custom Android/iOS malware families to compromise victims, particularly in Southeast Asia, via impersonation of government services.
Financially motivated phishing campaigns impersonating Indonesia’s tax platform to steal money from Android users (notably during tax season).
GoldFactory is a financially motivated cybercriminal group targeting Southeast Asian mobile users with fake banking apps to distribute Android malware for financial theft.
GoldFactory is a financially motivated cybercrime group targeting mobile users in Southeast Asia by distributing modified banking applications that deliver Android malware. They impersonate government services and local brands to trick victims into installing malware, enabling remote access, credential theft, and financial fraud.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.