GoldDigger is an Android banking trojan associated with the Chinese-speaking financially motivated threat actor GoldFactory. First publicly documented in 2023, it is designed to steal financial information and enable on-device fraud against mobile banking users. Reported victimology includes campaigns affecting users in South Korea, Indonesia, Thailand, South Africa, and the United Kingdom, with lures impersonating airlines, retailers, and in broader GoldFactory activity, government-related services and modified banking applications.
On infected devices, GoldDigger abuses Android accessibility services to monitor user activity, interact with banking applications, inject input, and mimic legitimate user actions in order to initiate fraudulent transactions. It captures banking credentials through fake overlays and supports real-time screen access for operators. Reported command capabilities also include collecting contacts and SMS messages, capturing input from applications, requesting additional permissions such as accessibility and location access, recording audio and video, streaming media, opening URLs, and launching applications. GoldDigger has also been described as running targeted apps inside a virtualized environment to observe runtime behavior and intercept credentials and other sensitive data.
GoldDigger uses anti-analysis and defense-evasion measures, including obfuscation with the dpt-shell packer, encryption of native logic, and checks intended to disrupt dynamic analysis and debugger attachment. It communicates with operators over WebSocket-based command-and-control channels. The malware is part of a broader GoldFactory mobile fraud ecosystem that has also included GoldPickaxe and GoldDiggerPlus, reflecting a sustained focus on mobile financial theft and remote fraud operations against Android users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The third Android banking trojan to come under the security radar is GoldDigger, which was first documented by Group-IB in October 2023 as capable of carrying out on-device fraud.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
GoldDigger makes use of a sophisticated packer called "dpt-shell" to obfuscate its code and resources in an attempt to resist analysis.
The current GoldDigger campaign mainly impersonates airline companies and shopping retailers
the Android malware can display full-screen "system update" overlays to conceal its background actions and deploy an invisible transparent overlay to capture touch and harvest PIN codes.
The malware abuses accessibility services to monitor user activity, capture credentials, and interact with banking applications while operating with limited visibility to the victim.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan used for on-device fraud. It abuses accessibility permissions to inject input into banking apps, initiate fraudulent transactions, capture credentials with fake overlays, provide real-time screen access, collect contacts and SMS, record audio/video, and communicate with C2 over WebSocket.
Android malware family that steals financial information and enables fraud on compromised devices. It abuses accessibility services to monitor user activity, capture credentials, and interact with banking applications while remaining minimally visible to the victim.
Custom mobile malware family used by the GoldFactory cybercrime group; specific functionality not described in the provided excerpt.
Android banking trojan used against users in South Korea, Indonesia, and Thailand.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.