GoldPickaxe is an Android banking trojan associated with the GoldFactory cybercrime group and part of the broader GoldDigger malware cluster. It targets users of mobile banking, e-wallet, and other financial applications, with campaigns concentrated in Southeast Asia and notable focus on Indonesia. The malware has also been observed affecting victims in Malaysia, Singapore, Saudi Arabia, and the United States.
GoldPickaxe is typically delivered through phishing infrastructure that impersonates legitimate services and lures victims into installing a dropper application. The initial-stage app contains limited malicious functionality and uses Android’s SessionInstaller API to deploy a second-stage payload. The payload stores core logic in encrypted components that are decrypted and loaded dynamically at runtime, and the malware employs multiple anti-analysis and concealment measures, including manifest tampering that disrupts common reverse-engineering tools and removal of launcher visibility to hinder discovery.
Once active, GoldPickaxe supports extensive post-compromise control and data theft. Reported capabilities include theft of banking-related credentials, lock-screen PINs, patterns, and passwords; collection of SMS messages, contacts, call logs, device and installed-application information; keylogging; screen capture and screen sharing; overlay-based social engineering; text injection; gesture simulation; and remote downloading and installation of additional applications. It also abuses accessibility-related functionality to scrape on-screen content and facilitate device control.
A distinguishing feature of newer GoldPickaxe variants is biometric and identity-data theft. The malware can prompt victims to upload identity documents and record facial video, enabling theft of face biometrics that could be abused to defeat remote identity-verification and e-KYC workflows used by financial institutions. Samples have contained embedded target lists of Indonesian banking applications, indicating tailored fraud operations against specific regional institutions.
GoldPickaxe communications are encrypted, including command-and-control traffic protected through native code and per-request cryptographic material. Overall, the malware represents a mature mobile banking-fraud platform combining credential theft, surveillance, remote device manipulation, and defense evasion to support account takeover and financial fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The GoldPickaxe banking Trojan is back, and it hunts your face. Zimperium’s zLabs team found a new Android variant that steals biometric data, bank logins, and text messages.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan in the GoldDigger suite that steals biometric/face data, lock-screen credentials, SMS logs, contacts, keystrokes, screen content, and can display overlays, inject text, simulate gestures, remotely control the device, and fetch/install additional apps.
Mobile banking trojan targeting Android devices. It is delivered via phishing sites spoofing KuaiBo, uses a dropper plus secondary payload, abuses Android SessionInstaller, dynamic code loading, Accessibility Services, and Media Projection, and steals SMS, contacts, call logs, installed app data, lock-screen credentials, ID cards, and facial biometric data while enabling screen sharing, keylogging, overlays, gesture simulation, and remote APK download.
Custom mobile malware family used by the GoldFactory cybercrime group; specific functionality not described in the provided excerpt.
Custom banking trojan targeting Android and iOS devices, used to steal financial information and facilitate fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.