


Perceptive Security
SOC/SIEM Consultancy

GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
Published:
4 December 2025 at 09:27:00
Alert date:
5 December 2025 at 08:03:22
Source:
thehackernews.com

GoldFactory cybercriminal group launched a fresh campaign since October 2024 targeting mobile users in Indonesia, Thailand, and Vietnam. The attackers distribute modified banking applications that serve as conduits for Android malware while impersonating government services. The campaign has resulted in over 11,000 infections across Southeast Asia. The malware targets banking credentials and financial information through fraudulent mobile applications. This represents an active, large-scale financial threat to mobile banking users in the region.
Technical details
Mitigation steps:
Affected products:
Android banking applications
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.