GoldFactory is a financially motivated, Chinese-speaking cybercrime group focused on mobile banking fraud, primarily against Android users. The group is associated with the GoldPickaxe, GoldDigger, GoldDiggerPlus, GoldKefu, Gigabud, and Gigaflower malware families. Its operations have targeted users across Southeast Asia as well as Latin America, Africa, the Middle East, Europe, and North America. GoldFactory commonly uses phishing sites, telephone calls, messaging platforms, social-media content, and fraudulent application-store pages to induce victims to sideload apps impersonating government agencies, airlines, tax services, retailers, and financial institutions. Its Android malware abuses Accessibility Services, overlay permissions, and battery-optimization exemptions to support remote device control, application discovery, credential and lock-screen-code theft, keylogging, screen surveillance, and unauthorized transactions. The group has also modified otherwise legitimate banking applications and used runtime-hooking frameworks to bypass security controls, conceal malicious activity, and facilitate on-device fraud. Gigabud operations use Vwork, a weaponized fork of the Shelter application-cloning tool, to create Android Work Profiles containing cloned or tampered banking applications. This profile separation can isolate banking activity from risk signals associated with malware in the victim’s personal profile. GoldPickaxe additionally supports theft of identity documents, facial biometric recordings, SMS messages, contacts, call logs, and device data, as well as gesture simulation, screen capture, and additional-payload installation. GoldFactory activity has been attributed by multiple security researchers based on malware-development and operational links, including Chinese-language development artifacts and shared infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to a mobile-banking-fraud campaign using the Gigabud Android banking trojan and Vwork app-cloning tool to create cloned banking applications in Android Work Profiles, evade fraud detection, and facilitate fraudulent transactions.
Weaponized the Vwork Android application-cloning tool as an add-on for the Gigabud banking trojan. Vwork abuses Android Work Profiles to clone banking apps into an isolated space, conceal Gigabud from security detection, and retain remote control over victims' devices. Confirmed infections occurred in Indonesia, with targeting across Asia, the Middle East, Africa, and Latin America.
Conducting Android banking-trojan campaigns using Gigabud and the Vwork work-profile application to install tampered banking apps in a separate Android work profile, bypassing banking-app malware checks and enabling fraudulent transactions.
Conducting Android banking fraud using the Gigabud banking trojan and Vwork, a weaponized app-cloning tool that creates an isolated Android work profile to evade detection and transact through cloned banking applications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.