GoldDigger

Description

(Group-IB) Codenamed GoldDigger by Group-IB’s Threat Intelligence unit, the Trojan has been active since at least June 2023. The malicious application impersonates a Vietnamese government portal and an energy company and abuses the Android Accessibility service to extract personal information, steal banking app credentials, intercept SMS messages, and perform various user actions. The number of infected devices and the amount stolen remains unknown.

Names

Name
GoldDigger

Category

Malware

Type

  • Banking trojan

Information

Malpedia

Other Information

Uuid

3695f51b-e7ca-44fb-a187-3299950ff6f2

Last Card Change

2024-03-07