GoldDigger Banking Trojan Targets Victims in Asia

A newly discovered Android banking trojan, named GoldDigger, has been identified as targeting various financial applications. Its main objective is to steal funds from victims and establish unauthorized access to infected devices.

According to Group-IB, the malware is specifically targeting more than 50 banking, e-wallet, and cryptocurrency wallet applications in Vietnam. There are concerns that this threat may expand its operations to other parts of the Asia-Pacific (APAC) region and Spanish-speaking countries.

The malware was initially detected by a Singapore-based company in August 2023, although evidence suggests it has been active since June 2023.

GoldDigger Abuses Accessibility Services to Infiltrate

While the exact extent of the infections is unknown, the malicious apps have been discovered masquerading as a Vietnamese government portal and an energy company. They request intrusive permissions under the guise of data collection, primarily exploiting Android's accessibility services. These services, designed to assist users with disabilities, are used by GoldDigger to interact with target apps, extract personal information, steal banking app credentials, intercept SMS messages, and carry out various user actions.

Granting permissions to the malware also grants it full access to user activities, allowing it to monitor bank account balances, capture two-factor authentication (2FA) codes, record keystrokes, and enable remote access to the infected device.

The attack chains that distribute GoldDigger involve fake websites that impersonate Google Play Store pages and counterfeit corporate websites in Vietnam. This suggests that these links may be spread to victims through smishing or traditional phishing techniques.

However, the success of the campaign relies on users enabling the "Install from Unknown Sources" option, which permits the installation of apps from sources outside of the official app store.

GoldDigger is one of several Android banking trojans that have emerged in recent months, adding to the already substantial number of similar malicious tools circulating in the wild.

October 6, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.