A new iOS and Android trojan ‘GoldPickaxe’ developed by the Chinese threat group named GoldFactory employs a social engineering scheme to trick victims into scanning their faces and ID documents, which may be used to generate deepfakes for unauthorized banking access.
Singapore-headquartered Group-IB spotted the new malware which is part of a malware suite developed by the Chinese threat group known as ‘GoldFactory,’ who are also responsible for other malware strains such as ‘GoldDigger’, ‘GoldDiggerPlus,’ and ‘GoldKefu.’
According to the Group-IB analysts, the attacks primarily targeted the Asia-Pacific region, mainly Thailand and Vietnam. However, the techniques employed could be effective globally, and it could be adopted by other malware strains as well.
The distribution of Gold Pickaxe started in October 2023 and is considered part of a GoldFactory campaign that began in June 2023 with Gold Digger.
Victims are sent phishing or smishing messages on the LINE messaging app that are written in their local language, impersonating government authorities or services.
The messages try to trick them into installing fraudulent apps, such as a fake ‘Digital Pension’ app hosted on websites impersonating Google Play.
For iOS (iPhone) users, the threat actors initially directed targets to a TestFlight URL to install the malicious app, allowing them to bypass the normal security review process.
When Apple remove the TestFlight app, the attackers switched to luring targets into downloading a malicious Mobile Device Management (MDM) profile that allows the threat actors to take control over devices.
GoldPickaxe prompts the victim to record a video as a confirmation method in the fake application. The recorded video is then used as raw material for the creation of deepfake videos facilitated by face-swapping artificial intelligence services.
The Trojan then operates semi-autonomously, manipulating functions in the background, capturing the victim’s face, intercepting incoming SMS, requesting ID documents, and proxying network traffic through the infected device using ‘MicroSocks.’
The Android version of the trojan performs more malicious activities than in iOS due to Apple’s higher security restrictions. Also, on Android, the trojan uses over 20 different bogus apps as cover.
GoldPickaxe can also run commands on Android to access SMS, navigate the filesystem, perform clicks on the screen, upload the 100 most recent photos from the victim’s album, download and install additional packages, and serve fake notifications.
While GoldPickaxe can steal images from iOS and Android phones showing the victim’s face and trick the users into disclosing their face on video through social engineering, the malware does not hijack Face ID data or exploit any vulnerability on the two mobile OSes.
Biometric data stored on the devices’ secure enclaves is still appropriately encrypted and completely isolated from running apps.
To mitigate the risks posed by GoldFactory and its suite of mobile banking malware, it’s strongly advised not to click on suspicious links, install any app from untrusted sites and periodically review the permissions given to apps, particularly those requesting for Android’s accessibility services.

















Comments