Security News > 2024 > February > New ‘Gold Pickaxe’ Android, iOS malware steals your face for fraud

New ‘Gold Pickaxe’ Android, iOS malware steals your face for fraud
2024-02-15 08:00

A new iOS and Android trojan named 'GoldPickaxe' employs a social engineering scheme to trick victims into scanning their faces and ID documents, which are believed to be used to generate deepfakes for unauthorized banking access.

The new malware, spotted by Group-IB, is part of a malware suite developed by the Chinese threat group known as 'GoldFactory,' which is responsible for other malware strains such as 'GoldDigger', 'GoldDiggerPlus,' and 'GoldKefu.

Group-IB says the Android version of the trojan performs more malicious activities than in iOS due to Apple's higher security restrictions.

It is essential to clarify that while GoldPickaxe can steal images from iOS and Android phones showing the victim's face and trick the users into disclosing their face on video through social engineering, the malware does not hijack Face ID data or exploit any vulnerability on the two mobile OSes.

New Xamalicious Android malware installed 330k times on Google Play.

Google tests blocking side-loaded Android apps with risky permissions.


News URL

https://www.bleepingcomputer.com/news/security/new-gold-pickaxe-android-ios-malware-steals-your-face-for-fraud/