Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
6 malware families

GoldFactory

Also known asGoldFactory

GoldFactory is a financially motivated Chinese-speaking cybercrime group targeting mobile users in Southeast Asia, particularly in Indonesia, Thailand, and Vietnam. The group has been observed since at least October 2024 impersonating government services and other trusted entities to distribute modified banking applications and Android malware. Reported lures include impersonation of government services and Vietnam's public power company EVN, with victims contacted via phone calls and messaging apps such as Zalo and redirected to fake Google Play landing pages. Group-IB linked GoldFactory to campaigns using custom malware families including GoldPickaxe, GoldDigger, and GoldDiggerPlus, and connected the group to the Gigabud Android malware. Recent campaigns have delivered Android malware and remote access trojans including Gigabud, MMRat, and Remo. GoldFactory has also developed a newer Android malware variant, Gigaflower, identified through the group's infrastructure. The group's operations focus on mobile banking fraud. Their malware abuses Android accessibility services for remote control and injects malicious code into legitimate banking apps while preserving normal app functionality. Reported runtime-hooking malware families used in modified apps include FriHook, SkyHook, and PineHook, which leverage the Frida gadget, Dobby, and Pine frameworks respectively. These capabilities are used to bypass security features, hide malicious activity, prevent screencast detection, spoof app signatures, hide installation sources, implement custom integrity tokens, and obtain account balances. Gigaflower reportedly supports 48 commands, including real-time device streaming, keylogging, UI reading, gesture automation, fake screen serving, and extraction of data from ID card images; a QR code scanner for Vietnamese identity cards was under development. According to the provided reporting, GoldFactory's latest wave was first detected in Thailand and then spread to Vietnam and Indonesia. Group-IB identified over 300 unique samples of modified banking apps and more than 3,000 related artifacts, resulting in at least 11,000 infections, with the majority of altered apps targeting the Indonesian market. The group previously used iOS malware in earlier campaigns tied to KYC process abuse, but has reportedly shifted away from iOS and now instructs victims to use Android devices, likely due to stricter iOS security.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • finance
MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
TA0005
Stealth
1 technique
T1036
Masquerading
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.