Group-IB has uncovered a mobile-app phishing campaign in the Asia-Pacific region, tracked back to GoldFactory.
This is the group notorious for its ability to steal facial recognition data to access sensitive information.
GoldFactory are injecting legitimate banking apps with malicious code, combining hooking frameworks, remote-access trojans, social engineering and real-time streaming to hijack devices and steal from users across Southeast Asia with implications for other regions globally.
By injecting malicious code into real apps, the group creates fully ‘Trojanised’ versions that look and behave normally while secretly stealing credentials, monitoring activity and enabling fraud.
GoldFactory uses a suite of advanced hooking malware families – including SkyHook, FriHook, PineHook and Gigabud variants – to bypass app-integrity checks, hide malicious activity and take full control of infected devices. These tools allow attackers to capture sensitive data, automate on-screen actions and even remotely view and operate the victim’s phone.
The operation relies on targeted social-engineering campaigns that impersonate local government and service providers, pushing victims to sideload malicious apps from fake websites. This approach enables rapid deployment across countries, exposing tens of thousands of users and dozens of financial institutions to high impact banking fraud.
“Their modus operandi is sophisticated banking fraud,” said Craig Jones, former Cybercrime Director at Interpol, speaking on the GoldFactory episode of Masked Actors.


