Go back

GoldFactory: The cybercriminals who want to steal your face

23m 46s

GoldFactory: The cybercriminals who want to steal your face

In May 2024, a new threat called Gold Pickaxe, an iOS Trojan, emerged as part of a cluster of aggressive banking Trojans attributed to the Gold Factory cyber criminal group. The malware aims to access users' facial recognition data to create deepfakes for bank account fraud. The financial impact targets finance companies and customers in the Asia Pacific region, particularly Vietnam and Thailand. User awareness, business protection measures, and collaboration with law enforcement are crucial to combat cyber threats effectively. The collaboration between organizations like Group IB and law enforcement, such as Interpol, plays a vital role in identifying cybercriminals, conducting targeted operations, and making communities safer by addressing cybercrime effectively through data sharing and coordinated efforts.

Transcription

4102 Words, 23907 Characters

In May of 2024, a new threat was uncovered and with it, an entirely new method of theft. Part of a cluster of aggressive banking Trojans, this sophisticated mobile malware dubbed Gold Pickaxe, was a first. It was an iOS Trojan, a sibling of its Android predecessor, and it had just one aim, to get access to users' facial recognition data. This threat cluster has been attributed to a single actor codenamed Gold Factory. The cyber criminals that want to steal your face, I think we should probably start at the start. Let's talk about Trojans, Nick. Tell us what they are, how do they work? Yeah, for sure. So a Trojan is basically a type of malware that's trying to hide itself, disguise itself as essentially legitimate software. Cyber criminals will develop this seemingly legitimate software to try to gain access to your mobile device or PC computer, etc. And it's interesting to maybe look at the history of where the word Trojan comes from. And if you go back to basically the Greek army infiltrating Troy, they basically tried to hide inside of a wooden horse and then eventually, surprise, surprise, entered into Troy and had their army inside the castle walls, if you will. So that's essentially what it is, what it does at a very simple level. Yeah, I'm trying to imagine were things easier or harder back then in the days of Troy compared to today. So these things have been around forever, basically, but what's new here from a technological perspective? I think one of the most interesting discoveries in gold pickaxe from Gold Factory cyber criminal group is really some of the tactics and techniques that this malware employs. I think with all of the advancements of artificial intelligence, you know, researchers have kind of been forecasting that threat actors will start to use this in their tactics and their techniques. And basically what this malware does after it gains accessibility services and access to your mobile phone is it will start to record video of an individual pretending to go through the KYC process with their driver's license and things like that. And after the malware essentially records this video, the threat actor can reproduce that with deepfake activities and register in their bank account, make a transaction, something like this. So that's really what's exciting to me anyway about this new malware. Yeah, that's crazy because it's one thing to have your password stolen. I've got passwords stolen. There's probably some you can go and see them on the dark web now of mine. But I can change those, right? I can go and do a password reset, I can have multi-factor authentication, but I can't change my face. Unless you're Nicholas Cage, I guess, yeah. Face off. So Nick, the Gold Factory group, what do we know about them so far? Yeah, so there's actually not a lot of public information available. But what we do know is that the group is currently active in the Asia Pacific region. And we believe them to be a well organized Chinese speaking cybercriminal groups with actually close connections to gigabud, which was a disruptive banking trojan that was first discovered in 2022. In fact, these sophisticated banking trojans seem to be the group's MO or Motosaparende. And the flashy gold theme name comes from the lines of code that actually group IB's researchers discovered in their first threats. So actually in October of 2023, this was when group IB first released information about a previously unknown Android Trojan. And the researchers actually nicknamed Gold Digger. So in seven months following the release of that report, further investigations actually uncovered not only an entire cluster of aggressive banking trojans, but a first of its kind with iOS versions as well. Yeah, the iOS side of it is kind of terrifying for me because, you know, historically, Android has always been the sort of weaker system. And I've felt very secure using iOS because those exploits are harder to come by seeing things like this and hearing that it's possible on iOS is very interesting. So gold pickaxe then, how does that work? Yeah, so like most schemes, malicious apps are really sent via links, right? So first, the threat actors are trying to communicate with potential victims through different messengers and encouraging them to install the malicious app via the links. So for Apple users, it was actually interesting that they were encouraged to download test flight. So Apple's kind of testing for different applications. And then Android users were encouraged to download mobile device management solution. With this successfully installed on the user's device, the cyber criminals were able to then install their Trojan remotely. So they gained the necessary permissions on the device. And then the Trojan was basically encouraging different users to record a video of themselves with, you know, driver's license or other KYC documentation for a fake application. So that's where they got the video from. So the video was then used as raw material for this cyber criminal group to actually create their deep fakes and perform the final cash out procedures. They could install different banking applications on their own devices and use that raw material to actually bypass the preventative measures that the bank has. Yeah, that's wild. That is the last thing that you want to happen to your face. So Nick, the financial impact of the damage done by gold factory isn't really known yet, but do we know who the victims are? Yeah, the victims are primarily finance companies and their customers. And predominantly the group has been targeting the Asia Pacific market with a focus on Vietnam and Thailand. What's interesting, I think to note though, is that, you know, with this new tactic and technique, cyber criminals often like to test, to validate and to be ready to scale, right? So it's very likely that we'll see this group expand their operations once they've perfected their craft, if you will, and expand this operation outside of just a specific markets. And are they going after like regular people? Or are they going after people who work in businesses or is it a mix? You know, what's the target profile? Yeah, I think most importantly is they're going after people, right? They want to get access to people that have specifically bank accounts, right? So the ability for a Trojan to review what applications are on a specific device is important. And then target those individuals that have, yeah, bank account access, right? So ultimately, this is a financially motivated cyber criminal group. So they want to target people, capture their likeness, their face, application process, and then perform the cash out procedures once they've done that. Okay, so let's talk about the victims. Nick, you've been a Group IB for a long time. You've got a wealth of experience working with businesses and people who have, you know, been victims of cyber attacks. What type of impact does an attack like this have on people? Well, I think the risks are really twofold, right? So one is the financial loss for the individual, the user, the citizens, etc. And the second is the risk for the business as well, right? And so there can be a lot of reputational damage done to an organization if, you know, someone is applying for loans using their facial biometrical data and it's successful against a specific business. It also depends on how widespread it is. Obviously, I mentioned before that cyber criminals want to scale their operations. So if they're able to scale up loan applications or account takeover at financial institutions, the financial impact could be very large, but also the risk and for the reputation of the business as well. It's really important, I think, to take note of a new tactic and technique being employed by these cyber criminals for financial gain. Because while it may target the Asia Pacific market right now, it's important to understand that this tactic and technique is successful, which it seems it has been, will be exported to other markets. So really understanding, you know, how are my KYC processes today? Can I understand as a business the entire user session? You know, do I know if it's actually my customer logging into the bank account or another Android device that the cyber criminal is performing these deep fake activities on to conduct account takeover? So yeah, learning from what this is and, you know, take note and make adjustments so that you can defend against this attack for the future. Yeah, definitely don't just close your eyes and hope for the best. That won't help. Obviously, it's important that, you know, businesses report crimes and things to law enforcement, because that helps in so many ways. We're very fortunate today to have Craig Jones with us who spent over five years at Interpol as the director of cyber crime. Craig, great to have you here. What can you tell us about the role of deep fakes and AI in crimes like these? Is this common? Yeah, hi, Gary. Hi, Nick. Thanks for inviting me on. Yeah, they're becoming more common, unfortunately. And I think this is where criminals are exploiting either vulnerabilities and systems or networks or people effectively. And then using tools which we use for our everyday life online to facilitate their ability to commit cyber crime. And they're testing these new methods and they're seeing how they can adapt the new methods, whether it's deep fake, whether it's AI. And the main purpose of this, I think you've already been discussing is, you know, from a criminal side of you, it's around that financial gain. It's how do they use what's available to them to commit criminal acts? But normally for financial gain, that's the motivation behind these crime groups, whether it's an individual, whether it's a group coming together online, whether it's a village coming together because, you know, they may not be able to have the economy there and the digitalization that's now available to them is opening up new opportunities, not just for us to start new industries, but also for the criminals. Are we likely to see this type of thing for sale in the same way that we see like ransomware as a service? Yeah, I think, you know, when we look at these businesses, they almost start to operate as franchises. So if it becomes successful, how do you grow any business? There is a certain volume amount that you can work to effectively. And, you know, the volume and scale of cyber crime, we've seen increasing exponentially over the last 10, 15 years, we started with those denial of services attacks, which, you know, people used to do for fun, or they would go on to or get into someone's network or systems, because that was fun to do. But then they realized they could commoditize that so that that information, that data became valuable. And then as the online initializations increase, the way we're operating now and our finances are operating in the online space as well, and the virtual currencies, that gives the criminals an opportunity to sort of, as I said already, to exploit that. And, you know, when this first launched, Goldfactory's iOS Trojan was available through Test Flight, as Nick said earlier, that obviously helped it appear legitimate. Thankfully, it didn't last long. But once that was removed, Thread Actors had to, you know, employ new techniques, particularly social engineering. Can we talk about that a little bit? You know, these schemes are designed to bring victims in to install malicious software. What are the warning signs of social engineering? Yeah, I mean, that's that's on lots of different levels. So, you know, we can talk about, you know, you receive that email with, well done, you've won X or Y, or this is the latest update, you need to update this on your phone immediately, because you're going to be at risk. So it plays on vulnerabilities. On the one hand, it can prey on people's insecurities online. So it could be an individual, or it could be quite specifically targeted at a business, targeting maybe a chief financial officer within a company, where someone's pretending to be a CEO or something like that. And the criminals will be using different scripts, whether they're automated scripts, or they might seem quite innocuous to start with, you know, you just get that pop up on your phone saying, Oh, hi, it's so and so. And you then respond to it when you start that dialogue. And what they try to do within that is gain your trust. How do we protect ourselves and our businesses from threat actors like gold factory? Yeah, well, I think protecting ourselves is really all about awareness, right? So individuals need to be aware of how to actually protect themselves. I always think to my mother, actually, and I've even trained her using real world examples about how to use virus total to scan a link to see if it's bad or not. So I think user awareness and training just to make sure your customers know not to click on links that are sent to you from different messengers is very important or how to scan a link on on VT. The second thing really is, you know, on the business, right? So I want to bank with a bank who is serious about protecting my money. And I think, you know, user education can only go so far and, you know, to really fight the bad guys and ensure that they don't have an impact to your organization. It's important to think about ways that you can counteract this threat. So I go back to what we do here at Group IB with fraud protection, and it's, you know, looking at the user session, can you identify if someone's video camera is being manipulated during the user session? Can you effectively and stickily fingerprint a device and a user based on their behavior and know that it's really your customer logging in or, you know, a new Android device that maybe is manipulating the camera? So, and I think it's important to look at from a business perspective, what is this threat? What are the tactics and techniques that are being employed now? And do I have the necessary measures in place to prevent it? So I think it's Nick's just explained there, there's quite a lot of technical stuff that can be done. But then we look at that sort of social engineering side we've touched on that briefly already. And that's about personal awareness. I remember many years ago when I was in law enforcement in the UK, we had this stranger danger program. And this was about that physical, you know, don't talk to strangers. And it was ingrained, but it was ingrained in a very, very early age of the school curriculum. And that comes back to that awareness, we have to start that as soon as the children gets, you know, a device in the hand three, four, five, six years old, parents should be educating them. It's almost like those conversations you have with your children. You need to be having that online conversation with them as well. And I think we're almost in this, not twilight zone, but moving across where you've got the digital natives coming in who got it from day one, where maybe maybe talking to myself when I was a child, we didn't have these things. So I've had to learn that. And sometimes it can seem a little bit dull, but you know, that that awareness is so important. Now governments are picking up on this. They're doing a lot of work in different countries around that awareness training, not just for individuals, but small media enterprise companies and for major companies as well. And again, it comes back to that target hardening. It's at what level do you put those interventions in effect? Do you use the internet when you're online? What's your personal habits about where are you likely to go and look online? What sites do you like where you may download something that's then going to affect your computer or something like that? On a global level, Craig, what sort of progress has teams like Interpol made towards taking down groups like Gold Factory? Oh, well, I mean, that's it's almost night and day from when we started. So I sort of think when I started back in the UK about 2012, 2013, leading a sort of regional cyber crime team, looking at the cases we were dealing with then. And you know, it really was a whole new way of law enforcement working, you know, we're just used to working in our local environment, protecting our local criminal, our local communities and going after local criminals, because we we knew our community, we knew the criminals in our in our community. And we've seen trends and patterns. Fast forward to where we are now, we're still there to police the community, prevention of crime, protection of life and property is really important. But what we don't see within that space is the criminal actors in the online space. And that's where companies such as Group IV and others, they have that information, they do that detection work. So they can detect. And then how do we share that information? So we look at many international companies now, that are global companies, they can share that information very, very readily and very, very quickly. But in terms of how law enforcement operates, we have legislation within each country. So this might be a crime in one country, but it may not be a crime in another country. So what we have is sort of a regional desk model at Interpol, where we have regional cyber crime officers effectively, for example, in Africa, who dock directly into Interpol and use our tools and platforms, and then share that data locally in Africa or in Asia and South Pacific or in Europe. So we still try to get that local policing model, but it's that global to local or local to global. And we've got to make sure we can share that information and Interpol channels are absolutely perfect for doing that about 196 countries. But then there's the prioritization of crime in countries as well. And it's not reported. Then there's not a problem. So it sometimes goes unseen in certain countries as well. So Interpol, like, how does that actually work? What does it look like? What's your sort of process for taking these groups done? So what Interpol is able to do with companies such as Group IB is do targeted operations. So we can first of all identify the victims. Now, last November to this February in 2025, Interpol ran an operation called Operation Red Card. We coordinated activities with the private sector government countries, and over 5000 victims were identified. And from those 5000 victims, we were then able to identify the criminals behind those cybercrime acts and over 300 suspects were identified. That led to arrests and then devices being seized. This is where that cybercrime model is becoming quite challenging for law enforcement because we're then pulling in more data and more information. And it's not just about arresting that criminal and interviewing a criminal. We then have to look through those devices because what happens then is we can then see more victims. So it's this inuous loop that law enforcement is going through. But the main aim is to sort of make our communities safer. Yeah, I can really see the advantages that the likes of, you know, law enforcement have when they collaborate with Group IB and other companies because Group IB has the technology, but law enforcement is law enforcement. You know, Group IB isn't going to go and arrest anyone, but they can certainly give the data to law enforcement to make that happen, right? Absolutely. And I think another thing, I suppose we back to 2019 when I first started to poll, we have our regional working groups and we were in a classroom in Nairobi and we probably had about 10 heads of cybercrime units from the African continent. So that's about 40 plus countries. We had 10. We had Group IB and others there. And, you know, it was really sobering listening to both officers from those countries describe the challenges they had. And I remember one that stuck out very clearly to me was, I think it was seriously, they'd gone in and raided a house where they thought human trafficking was taking place. So this is where, you know, people are sort of, you know, abducted and then trafficked through different countries. And when law enforcement went through the door, they basically found you'd be like a cybercrime factory. So there were people there in front of their laptops. You had one sort of a gang master there controlling it all. And the people were going online and committing crime. Now, they didn't know what they had at the time. And if we look where we are now, what we're seeing in sort of Southeast Asia, we're seeing people trafficked from one country into another country. They think they're going to a job. They get there, the passports are taken off them, they're then pushed across borders, corralled in different houses or places, and effectively are forced labor committing crime. And we're seeing this model evolving, because as we know, there's a shortage of people with online and criminals are the same. So they are looking about how they can sort of grow their organized crime groups and grow their franchise crime model as well. So when we look at the deep fakes and the AI side of this, there's quite often a human element under this as well. Thanks, Craig. I guess I'm not a doorkicker to arrest the bad guys. But yeah, it's always a pleasure to engage with law enforcement and actually make some disruption. That is really, I think, the driving factor for a lot of people working with Group IB is the mission to fight against cybercrime and they're constantly evolving. And I think that's what's so exciting to research cyber-enabled fraud is that the tactics and the techniques are always changing. And it's important to know where they're moving to, so you can help protect your business and the customers that you're working with. And I think Goldfactory is a prime example of that, sophistication, implementation of new scalable technology within their tactics and their techniques. And I'm excited to see what happens next. And we'll be here to research those bad guys as they start to pop up. Sure. And like, you know, Goldfactory is just one example. It's a, frankly, terrifying use case in my opinion. But that is the new reality we're facing here as security teams and law enforcement and we're going to have to keep up with it. You know, as we've discussed here, the more you know, the better prepared you are for this type of threat. So thanks for listening and we'll see you in the next one. Your data is valuable and it's under attack. Cyber espionage groups, financially motivated threat actors, ransomware attackers, and other criminal enterprises are on the rise. Working in secrecy to dismantle security perimeters, they spread like a virus through the web. Stoking geopolitical tensions, holding businesses to ransom and flooding criminal marketplaces with sensitive information. These groups thrive in secrecy now more than ever. Knowing who your adversaries are is critical. So join us as we ask who's behind the world's most prolific cyber criminal groups? What are their tactics, their motivations, and their impact? Who are the world's masked actors? Masked actors is an independent podcast from Group I.B., a leading voice in the fight against cyber crime. The threat landscape evolves quickly, but all information was correct at the time of recording and based on Group I.B.'s high-tech crime trends report 2025. Join in the conversation online using the hashtag masked actors and don't forget to subscribe so you don't miss an episode. Thanks for listening, see you next time as we uncover more of the world's top masked actors.

Podcast Summary

Key Points:

  1. Discovery of Gold Pickaxe, a new iOS Trojan, part of a cluster of aggressive banking Trojans.
  2. Gold Factory cyber criminal group behind the threat, targeting facial recognition data.
  3. Gold Pickaxe records video to create deepfakes for bank account fraud.
  4. Financial impact primarily on finance companies and customers in Asia Pacific region.
  5. Importance of user awareness, business protection, and collaboration with law enforcement to combat cyber threats.

Summary:

In May 2024, a new threat called Gold Pickaxe, an iOS Trojan, emerged as part of a cluster of aggressive banking Trojans attributed to the Gold Factory cyber criminal group. The malware aims to access users' facial recognition data to create deepfakes for bank account fraud. The financial impact targets finance companies and customers in the Asia Pacific region, particularly Vietnam and Thailand.

User awareness, business protection measures, and collaboration with law enforcement are crucial to combat cyber threats effectively. The collaboration between organizations like Group IB and law enforcement, such as Interpol, plays a vital role in identifying cybercriminals, conducting targeted operations, and making communities safer by addressing cybercrime effectively through data sharing and coordinated efforts.

FAQs

A Trojan is a type of malware that disguises itself as legitimate software to gain access to devices. Cyber criminals develop Trojans to infiltrate mobile devices and PCs.

Gold Pickaxe malware records videos of individuals going through processes like KYC using deepfake technology. This allows threat actors to impersonate victims for fraudulent activities.

The primary victims are finance companies and their customers, with a focus on the Asia Pacific market, particularly Vietnam and Thailand.

The financial impact is not yet fully known, but the group targets individuals with bank accounts for financial gain. They aim to capture personal data to perform fraudulent transactions.

Individuals should be aware of phishing links and avoid clicking on suspicious messages. Businesses need to implement measures to detect manipulations like deepfake videos and enhance user authentication.

Criminals use deep fake and AI to exploit vulnerabilities for financial gain. These technologies facilitate cyber crimes by manipulating digital content to deceive individuals and organizations.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.