Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

GoldFactory Ransomware Decryption & Data Recovery

  • Active
  • High
  • No public decryptor

GoldFactory is a Chinese-speaking mobile financial-crime group whose Android and iOS trojans - Gigabud, GoldPickaxe and GoldDigger - steal facial biometrics, ID photos and banking credentials to carry out fraudulent transfers. It encrypts nothing and drops no ransom note, so it is a fundamentally different threat from encryption ransomware.

First seen
2022-07
File extensions
No public information
Ransom notes
No public information
Affected platforms
Android / iOS

Family profile

File extensions
No public information
Ransom notes
No public information
Contact patterns
  • Fake Google Play pages that actually serve a sideloaded APK rather than a store install
  • Phishing domains impersonating government and public services: electricity utilities, tax offices, health departments, civil registration, national service portals
  • Fake download sites for media apps (the July 2026 variant used a spoofed KuaiBo streaming site)
  • A vishing call first, then a move to the locally dominant messenger (Zalo in Vietnamese cases, LINE in Thai ones) to walk the victim through installation
  • Cheap TLDs hosting samples in open directories, e.g. random-string domains under .icu and .com
  • No extortion mailbox, no Tor negotiation portal and no bitcoin address anywhere in the chain
Aliases / versions
Gigabud、Gigaflower、GoldPickaxe、GoldPickaxe.iOS、GoldDigger、GoldDiggerPlus、GoldKefu、Vwork(配套克隆器)、SkyHook / FriHook / PineHook(改造版银行应用)
First seen
2022-07
Status
Active
Operational status
Actively operating
Threat level
High
Affected platforms
  • Android
  • iOS
Tags
  • Mobile
  • Active
  • Phishing
  • Consumer targets
Decryptor
No public decryptor

This family does not encrypt files, so the question of a decryptor does not arise. GoldFactory ships mobile banking and remote-access trojans. The objective is facial biometric video, ID document photos, SMS one-time codes, banking credentials and the device lock code, after which a human operator moves money directly from the victim's handset. Extensions do not change, no ransom note is dropped, and the name appears in no No More Ransom or vendor decryptor listing - correctly so.

What has to be won here is time, not a key. In published cases the window between the trojan gaining Accessibility permission and funds leaving the account is often measured in tens of minutes. The effective actions are freezing the account and stopping payments, taking the device offline, and rotating every credential bound to it - not hunting for a decryption route.

Treat two kinds of third party with suspicion: anyone claiming to "decrypt" this family has misidentified it, and anyone promising to "recover stolen funds" or "delete leaked face data" is selling something that cannot be delivered. Biometric data cannot be recalled once exposed, and fund recovery sits with the bank and law enforcement. We do not chase funds for a fee and we do not negotiate.

Latest activity

  1. Group-IB disclosed that Gigabud now installs Vwork, a weaponised fork of the Shelter cloner, to clone banking apps into an Android work profile and transact from there, severing the link between malware alerts and fraud. Indonesia Feb-Jul 2026: ~1,469 devices, ~USD 960k losses.

    Sources
  2. The 360 Threat Intelligence Center's July 2026 financial-sector monthly report covered a new GoldPickaxe Android variant stealing device unlock credentials, biometric material and mobile financial data, attributing it to the APAC-active GoldFactory group.

    Sources
  3. Bangladesh e-GOV CIRT issued a GoldFactory/GoldPickaxe advisory: a new Android variant spread via a spoofed Chinese streaming site, injecting deepfake face streams through virtual cameras plus Frida/LSPosed to defeat e-KYC liveness; targeting now includes Bangladesh, Saudi Arabia and the US.

    Sources

Overview

The headline first: GoldFactory is not a ransomware family. It is a financially motivated, Chinese-speaking mobile crime group named publicly by Group-IB in February 2024. Its earliest core tool, Gigabud, dates to 2022, and the group's activity at scale began in mid-2023. The entry is kept in this family library because "my phone was taken over and money disappeared" is often described loosely as an infection or an extortion case, while the response window and the available countermeasures are nothing like those of an encryption incident.

Tooling lineage. GoldDigger (October 2023, against 50-plus Vietnamese financial institutions), GoldDiggerPlus with its embedded GoldKefu module and live voice operators, GoldPickaxe (October 2023 - the first known iOS trojan to harvest facial biometrics), the continuously developed Gigabud and its reworked test branch Gigaflower, and the companion cloner Vwork disclosed in September 2026. The group also uses Remo and MMRat as droppers and tampers with legitimate banking apps using Frida, Dobby and Pine, which Group-IB tracks as FriHook, SkyHook and PineHook.

Scale and geography. Group-IB's December 2025 report traced modified banking apps back to Thailand in October 2024, then Vietnam across late 2024 and early 2025, with a sharp rise in Indonesia from mid-2025: 300-plus modified app samples, 27 legitimate banking apps injected, 30 targeted financial institutions, more than 3,000 related samples and over 11,000 infections. The September 2026 Vwork report adds that Gigabud samples compatible with the cloner also target Brazil, Colombia, Egypt, Laos, Mexico, Morocco, the Philippines and Türkiye. No public reporting shows campaigns against mainland China financial institutions, but Chinese security vendors track the group in their financial-sector monthly reporting, and outbound business units and staff handsets used across borders remain inside its reach.

How to identify it

There is no extension and no ransom note here, so attribution rests entirely on device-side indicators:

  • Unusual install origin. The app arrives from a phishing page or a messenger link as an APK rather than from a store. Early iOS victims were pushed through TestFlight or talked into installing an MDM profile; since late 2025 the group has largely abandoned custom iOS malware and instead instructs victims by phone to "borrow an Android handset".
  • A suspicious permission bundle. Accessibility, draw-over-other-apps, screen capture, camera, SMS and contacts requested together, plus an exemption from battery optimisation. Granting Accessibility is the moment the operator gains live control of the device.
  • Interface anomalies. A fake login page appearing on top of the real banking app, an invisible overlay capturing the lock-screen code, and a black screen or "system update" panel shown while transfers are executed.
  • An unexpected work profile. A Work tab under Settings, passwords and accounts, briefcase badges on app icons, or the same banking app present in both the personal and work spaces - the signature of Vwork cloning.
  • Other technical markers. Apps with no launcher icon, encrypted payload files such as payload_dex.bin and dex_key.bin, and a SOCKS5 listener bound to 127.0.0.1.

Inverse test. If files genuinely carry a new extension and a note has been written to disk, this is not the family in question; re-identify against the relevant encryption family instead of applying the assumptions on this page.

Infection vectors

The entry point is social engineering, not exploitation, and the whole chain is driven by human operators:

  • Impersonating government and public services. Vietnamese cases impersonated EVN over "overdue electricity bills", provincial health departments announcing food-safety inspections, the national public service portal and the Ministry of Public Security. Indonesian cases impersonated Disdukcapil, the civil registration authority, using the national rollout of the digital KTP identity card to push a fake "IKD" app. Airline and tax-authority lures also appear.
  • A phone call plus a messenger. A call first, manufacturing urgency (disconnection, a fine, an administrative penalty), then a move to Zalo or a similar app where a "support agent" walks the victim through download and permissions. The GoldKefu module even embeds live voice operators who can talk to the victim in real time.
  • Fake app stores. Pages closely imitating Google Play that deliver an APK; when the store install "fails" or reports the app as "incompatible", the victim is redirected to sideload from an external site.
  • Chinese-language bait. The July 2026 variant was distributed through a spoofed KuaiBo streaming site, showing the lures are no longer limited to government themes.

For enterprises the transmission path that matters is the employee's personal handset - the same device typically carries corporate OA, mail, VPN tokens and banking apps, so one successful consumer-side social-engineering attempt can carry corporate credentials away with it.

Encryption behavior

There is no encryption. The question worth asking in this section is a different one: what do these trojans take, and how do they get past the bank's controls?

  • Collection targets. Facial recognition video and stills, ID card photographs, SMS and one-time codes, banking credentials, the device lock code, the full installed-app list (used to pick high-value banking targets), and live screen content read through Accessibility.
  • Defeating liveness checks. Stolen face material is run through AI face-swapping to produce deepfake video, which is injected into the banking app's capture pipeline using virtual camera software and hooking frameworks such as Frida and LSPosed. Because liveness verification checks the frame presented rather than its source, injection defeats even fairly mature detection.
  • Defeating bank-side fraud controls (the 2026 technique). After gaining permissions, Gigabud installs Vwork, a weaponised fork of the open-source cloner Shelter, which uses the Android Work Profile feature to create an isolated space, clones the banking app into it and transacts from there. A malware alert already raised in the personal profile does not fire again in the freshly provisioned work profile, so the bank sees an ordinary transaction from a "new device" and the link between the malicious signal and the fraudulent transfer is deliberately severed.
  • Measured impact. Group-IB observed roughly 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia alone between February and July 2026, with estimated losses of about USD 960,000.

Assess before you act

Recoverability assessment

There is no "data recovery" track in this kind of incident. The objectives are containment, limiting spread, and preserving evidence. We do not pay ransoms, do not negotiate and do not promise to recover funds.

1) Stop the financial bleeding (minutes matter). Contact the bank immediately to freeze accounts, reverse unsettled transactions and disable mobile banking and quick-pay, and report to law enforcement so payment interdiction can begin. Unbind every payment and token application from the device at the same time.

2) Handling biometric and identity-document exposure (irreversible - reduce dependence instead). Face and document data cannot be recalled. The practical response is to make them less useful: move high-risk operations off face-only verification onto multi-factor combinations (hardware tokens, non-SMS OTP, in-branch review), reissue the exposed identity documents, and place monitoring or blocks on credit, telecom SIM issuance and third-party payment channels.

3) Credential and account rotation across the device's full radius. Treat every account ever signed in on that handset as compromised - corporate mail, OA, VPN, remote access, cloud storage, code repositories and internal systems. Rotate passwords, revoke sessions and tokens, and re-enrol MFA. SMS codes were worthless while the device was controlled, so every self-service flow bound to them must be reset.

4) Device forensics before wiping. With the device offline, preserve a device image, the installed-app inventory, Accessibility grant records, the work profile creation timestamp, and call and message logs to establish the infection point and the operator's activity window; check specifically for Vwork and cloned apps. Factory-reset only after collection - wiping first to "get it working again" destroys the only evidence there is.

5) Enterprise impact assessment. Once the handset carried a corporate identity, this stops being a personal matter. Assess whether corporate accounts were accessed, whether anomalous logins or data egress occurred, whether personal-information breach notification duties are triggered, and quarantine then re-enrol the device under MDM and zero-trust policy.

Our response plan

Hit by GoldFactory ransomware? What to do

  1. Disconnect, stop payments, preserve evidence

    Put the handset into airplane mode and turn off Wi-Fi to cut the operator's control channel, and in parallel have the bank freeze the account and stop payments, then file a police report. Do not reset the device, uninstall suspicious apps or clear call and message history - these are the only basis for establishing the infection point and the operator's window. Preserve the handset itself along with the phishing link, calling number and chat screenshots.

  2. Family identification and device forensics

    Extract the app inventory, install sources, permission grant records and work-profile creation timestamp to determine which strain is present - Gigabud, GoldPickaxe or Gigaflower - and whether a Vwork clone environment or a tampered banking app such as SkyHook exists. Confirm the family really applies: a rewritten extension or a dropped note means the case belongs to an encryption-family identification workflow instead.

  3. Exposure and compliance assessment

    Inventory affected assets using the device as the radius: face and document material, the SMS channel, banking and payment accounts, and corporate mail, OA, VPN and cloud-storage accounts together with their live sessions. Assess whether corporate data left the environment or anomalous logins occurred, determine whether personal-information breach notification duties are triggered, and deliver a prioritised action list rather than a general conclusion.

  4. Credential rotation and authentication hardening

    Wipe and rebuild only after collection is complete. Rotate passwords, revoke sessions, reissue tokens and re-enrol MFA for every account tied to the device; temporarily move high-risk flows off face or SMS verification onto hardware tokens or manual review; reissue the exposed identity documents and place monitoring on the associated financial and telecom channels.

  5. Attribution, hardening and sign-off

    Reconstruct the full chain - call, messenger, phishing domain, sideload, permission grant, cloning and transfer - and submit domains and samples for takedown. On the enterprise side: block sideloading and unknown-source installs through MDM, monitor for unexpected work-profile provisioning, restrict Accessibility grants, separate work and financial apps across devices or accounts, and validate the result with a simulated social-engineering exercise.

Risk warning

What not to do

  • Do not go looking for a decryptor - this family encrypts nothing, and any tool or service claiming to decrypt it has misidentified the case.
  • Do not factory-reset the device or uninstall suspicious apps before collection; wiping destroys the infection timestamp, permission grant records and work-profile traces at once.
  • Do not keep using the handset to receive SMS codes for password resets; while the device is controlled, the SMS channel effectively belongs to the attacker.
  • Do not trust third parties promising to recover stolen funds or delete leaked face data - biometrics cannot be recalled, and fund recovery sits with the bank and law enforcement.
  • Do not install any further 'security check' or 'fund protection' app on instruction from a call or chat; a second-stage payload is the standard follow-up to that script.
  • Do not close the case after handling personal accounts - corporate mail, OA, VPN and cloud-storage credentials used on that device must be rotated in the same pass.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

GoldFactory Frequently asked questions

  • Is GoldFactory / Gigabud ransomware? Will my files be encrypted?

    No on both counts. These are Android and iOS banking and remote-access trojans whose goal is to steal face data, ID documents, SMS codes and banking credentials and then transfer funds directly. Extensions stay unchanged, no note is dropped and there is no Tor negotiation portal. If files on a PC really do have a new extension and a note, that is a different family and needs separate identification.

  • My facial data has already been stolen - can anything be done?

    Biometrics cannot be reset like a password and cannot be retrieved from the attacker, so the realistic response is to reduce their usefulness: move high-risk operations off face verification onto hardware tokens, non-SMS OTP or in-branch review, reissue the exposed identity documents, and set monitoring or blocks with banks, telecom operators and payment providers. Any service claiming it can delete leaked face data is not credible.

  • How do I check whether a Vwork work profile was created on the phone?

    Open Settings, passwords and accounts and look for a Work tab; check app icons for a briefcase badge; see whether the same banking app exists in both the personal and work spaces; and look for apps in the work profile that have nothing to do with work. A personal handset should have no work profile at all - if one appears, treat the device as controlled, take it offline for collection first, and reset only afterwards.

  • Should enterprises care about this family? Can a staff handset affect the company?

    Yes. A personal handset usually carries corporate mail, OA, VPN and MFA tokens at the same time, so one successful consumer-side social-engineering attempt can hand over corporate credentials, live sessions and the SMS channel together. Block sideloading through MDM, monitor for unexpected work-profile provisioning, restrict Accessibility grants, and bring 'handset under remote control' into the corporate incident plan rather than treating it as a private matter.

  • Are mainland China users and organisations targeted?

    Publicly reported victims concentrate in Vietnam, Thailand and Indonesia and are spreading into Latin America, the Middle East and Africa; there is no public record of a targeted campaign against mainland China financial institutions. But the group works in Chinese, its July 2026 variant used a spoofed Chinese-language streaming site as bait, and domestic vendors track it in their monthly reporting. Outbound operations, cross-border staff and handsets used abroad should be treated as carrying the same risk.