Is China’s GoldPickaxe Trojan Stealing Biometric Data to Hack Banks?

Security experts are warning about GoldPickaxe, a new Trojan from the Chinese cybercrime group GoldFactory. It targets smartphone users, stealing their facial biometric data to create deepfake videos aimed at circumventing banking security. The threat primarily affects users in Thailand and Vietnam, where it is spread through fake digital service apps. Victims are often lured by false government promises, such as digital pension services.

On Android, the Trojan is distributed via fake Google Play pages or deceptive corporate websites, whereas Apple’s TestFlight service or bogus mobile device management (MDM) profiles are the vectors for iOS, allowing the attackers to gain control of the devices. This sophisticated Trojan underscores the evolving threats in cybersecurity, particularly in biometric data exploitation, and highlights the need for heightened vigilance among smartphone users in the targeted regions.

Deeper Dive into GoldPickaxe’s Modus Operandi

The GoldPickaxe Trojan, drawing on data from prior breaches to boost its legitimacy, steps beyond identity theft and SMS interception, crucial for two-factor verification. Its most alarming function involves victims recording a video for a supposed ‘identity check’. This footage is used by attackers to create deepfakes, aiming to circumvent facial recognition in banking apps—a tactic that has caught the attention of Thai officials following a rise in fraudulent bank account accesses.

Rooted in the sophisticated cybercrime entity known as GoldFactory, GoldPickaxe exemplifies the creative and sophisticated nature of contemporary digital threats. This reinforces the need for enhanced protective measures, especially for biometric data, reflecting the dynamic landscape of cybersecurity. Thai authorities are closely monitoring the situation as these fraudsters skillfully manipulate biometrics, highlighting an era where vigilance and advanced security protocols are more critical than ever.

Explore more

How to Install Kali Linux on VirtualBox in 5 Easy Steps

Imagine a world where cybersecurity threats loom around every digital corner, and the need for skilled professionals to combat these dangers grows daily. Picture yourself stepping into this arena, armed with one of the most powerful tools in the industry, ready to test systems, uncover vulnerabilities, and safeguard networks. This journey begins with setting up a secure, isolated environment to

Trend Analysis: Ransomware Shifts in Manufacturing Sector

Imagine a quiet night shift at a sprawling manufacturing plant, where the hum of machinery suddenly grinds to a halt. A cryptic message flashes across the control room screens, demanding a hefty ransom for stolen data, while production lines stand frozen, costing thousands by the minute. This chilling scenario is becoming all too common as ransomware attacks surge in the

How Can You Protect Your Data During Holiday Shopping?

As the holiday season kicks into high gear, the excitement of snagging the perfect gift during Cyber Monday sales or last-minute Christmas deals often overshadows a darker reality: cybercriminals are lurking in the digital shadows, ready to exploit the frenzy. Picture this—amid the glow of holiday lights and the thrill of a “limited-time offer,” a seemingly harmless email about a

Master Instagram Takeovers with Tips and 2025 Examples

Imagine a brand’s Instagram account suddenly buzzing with fresh energy, drawing in thousands of new eyes as a trusted influencer shares a behind-the-scenes glimpse of a product in action. This surge of engagement, sparked by a single day of curated content, isn’t just a fluke—it’s the power of a well-executed Instagram takeover. In today’s fast-paced digital landscape, where standing out

Will WealthTech See Another Funding Boom Soon?

What happens when technology and wealth management collide in a market hungry for innovation? In recent years, the WealthTech sector—a dynamic slice of FinTech dedicated to revolutionizing investment and financial advisory services—has captured the imagination of investors with its promise of digital transformation. With billions poured into startups during a historic peak just a few years ago, the industry now