GoldPickaxe is an Android banking Trojan associated with the GoldFactory cybercrime ecosystem, a Chinese-speaking financially motivated threat cluster active against mobile users in Asia-Pacific and beyond. It is part of the broader GoldDigger malware suite and is designed to compromise users of mobile banking, e-wallet, and other financial applications, with campaigns particularly focused on Southeast Asia and observed targeting Indonesia in tailored operations.
GoldPickaxe is typically delivered through phishing infrastructure that impersonates legitimate mobile services and lures victims into installing a fake Android application. The initial package functions as a dropper with limited visible malicious logic, helping it evade superficial inspection, and then uses legitimate Android installation mechanisms to deploy a second-stage payload. The payload stores core functionality in encrypted components that are decrypted and loaded dynamically in memory. The malware also hides itself from casual discovery by omitting a launcher icon and employs anti-analysis measures including malformed manifest structures that disrupt common Android reverse-engineering tools.
Once active, GoldPickaxe provides extensive post-compromise control over the device. It steals lock-screen credentials, captures SMS messages, contacts, call logs, device and installed-application information, and performs keylogging. It can capture or share the device screen, scrape on-screen content through abuse of Accessibility Services, inject text, simulate gestures and clicks, and display fraudulent overlays to harvest sensitive information or conceal malicious activity. The malware also social-engineers victims into submitting identity documents and recording facial biometric video, creating a pathway for abuse of remote identity verification and e-KYC workflows used by financial institutions. In addition, it can receive commands to download and install further applications, extending the compromise.
GoldPickaxe uses encrypted command-and-control communications implemented through a native library, with per-request cryptographic material derived dynamically. Samples have contained embedded target lists of banking applications, indicating deliberate financial targeting and campaign customization. The malware has been observed across multiple countries, including Indonesia, Malaysia, Singapore, Saudi Arabia, and the United States, but its operational focus is mobile financial fraud against Android users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It's attributed to GoldFactory, a Chinese-speaking threat actor linked to other banking malware families targeting both Android and iOS, such as GoldPickaxe, GoldDiggerPlus, and GoldKefu.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another banking malware family linked to GoldFactory and targeting mobile platforms.
Android banking trojan in the GoldDigger suite that steals biometric/face data, lock-screen credentials, SMS logs, contacts, keystrokes, screen content, and can display overlays, inject text, simulate gestures, remotely control the device, and fetch/install additional apps.
Mobile banking trojan targeting Android devices. It is delivered via phishing sites spoofing KuaiBo, uses a dropper plus secondary payload, abuses Android SessionInstaller, dynamic code loading, Accessibility Services, and Media Projection, and steals SMS, contacts, call logs, installed app data, lock-screen credentials, ID cards, and facial biometric data while enabling screen sharing, keylogging, overlays, gesture simulation, and remote APK download.
Custom mobile malware family used by the GoldFactory cybercrime group; specific functionality not described in the provided excerpt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.