HomeSecurityGold Pickaxe trojan steals your face for deepfakes scams

Gold Pickaxe trojan steals your face for deepfakes scams

A new trojan affecting iOS and Android devices, dubbed 'Gold Pickaxe', uses social engineering to trick victims into scanning their faces and is believed to then use them to create deepfakes for unauthorized access to banking systems.

See also: Coyote banking trojan has infected 61 banking applications

Gold Pickaxe trojan deepfakes

The new malware, detected by Group-IB, is part of a malware suite developed by the Chinese threat group known as 'GoldFactory', which is responsible for other malware variants such as 'Gold Digger', 'Gold Digger Plus' and 'Gold Kefu'.

Group-IB reports that its analysts have observed attacks targeting primarily the Asia-Pacific region, most commonly Thailand and Vietnam. However, the techniques used may be effective worldwide and there is a risk that they could be adopted by other malware variants. The distribution of Gold Pickaxe began in October 2023 and is ongoing. It is believed to be part of a GoldFactory campaign that began in June 2023 with Gold Digger.

Victims receive phishing or smishing messages on the LINE app written in their local language, pretending to be from government authorities or agencies. The messages attempt to trick them into installing fake apps, such as a fake 'Digital Pension' app hosted on websites impersonating Google Play.

For iOS (iPhone) users, malicious actors initially used a TestFlight URL to install the malicious app, allowing them to bypass the normal security assessment process.

When Apple removed the TestFlight app, attackers turned to tricking targets into downloading a malicious Mobile Device Management (MDM) profile that allows perpetrators to gain control of devices.

See also: 10 new Android banking trojans appeared in 2023

After the Gold Pickaxe trojan is installed on a device in the form of a fake government application, it operates semi-autonomously, interfering with background operations, recording the victim's face to create deepfakes, intercepting incoming SMS, requesting identity documents, and routing network traffic through the infected device using 'MicroSocks'.

Group-IB reports that the Android version of the Gold Pickaxe trojan performs more malicious activities than iOS, due to Apple's higher security restrictions. Furthermore, on Android, the trojan uses over 20 different fake apps for cover.

Gold Pickaxe trojan steals your face for deepfakes scams

For example, Gold Pickaxe can also execute commands on Android to access SMS, browse the file system, perform on-screen clicks, upload the 100 most recent photos from the victim's album, download and install additional packages, and send fake notifications.

The use of victims' faces for bank fraud is a Group-IB case, also confirmed by Thai police, based on the fact that many financial institutions added biometric checks last year for transactions above a certain amount.

It is necessary to clarify that the Gold Pickaxe trojan can steal images from iOS and Android phones showing the victim's face (for deepfakes) and trick users into revealing their face in videos through social engineering, but without extracting Face ID or exploiting any vulnerability in the two operating systems.

Biometric data stored in the device's secure vaults is authenticated, encrypted, and completely isolated from the running applications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Chameleon banking trojan: New variant bypasses biometric checks

What is the function of banking trojans?

Banking trojans are malicious software designed to steal users' banking information. These software infiltrate a computer , often through phishing attacks or through attachments in spam emails.

Once installed, the banking trojan begins monitoring user activities, such as web and password entry. The collected information is then transferred to the attacker.

Banking trojans can also be used to install other malicious software on the user's computer, such as ransomware or spyware. This can lead to further security problems, such as the loss of personal or sensitive data.

The best defense is prevention. Users should be careful with the emails they receive, avoid clicking suspicious links, and use reputable security software to protect their computers.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS