GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
By posing as official agencies, cybercriminals connected to the financially driven group GoldFactory have been seen launching a new round of attacks against mobile users in Vietnam, Thailand, and Indonesia.
In a technical study released on Wednesday, Group-IB stated that the behavior, which has been seen since October 2024, entails the distribution of altered banking applications that serve as a conduit for Android malware.
GoldFactory, which is thought to have been active since June 2023, first came to light early last year when the cybersecurity firm with its headquarters in Singapore described how the threat actor used custom malware families like GoldPickaxe, GoldDigger, and GoldDiggerPlus to target both Android and iOS devices.
Evidence suggests that Gigabud, another Android...

