GoldDigger drains your bank account: new Trojan uncovered by Group-IB targets 50+ Vietnamese banks

Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, has discovered a new Android Trojan that specifically targets users of over 50 Vietnamese banking applications, electronic wallets, and cryptocurrency wallets, with the aim of stealing their funds. Codenamed GoldDigger by Group-IB’s Threat Intelligence unit, the Trojan has been active since at least June 2023. The malicious application impersonates a Vietnamese government portal and an energy company and abuses the Android Accessibility service to extract personal information, steal banking app credentials, intercept SMS messages, and perform various user actions. The number of infected devices and the amount stolen remains unknown.

Group-IB’s Threat Intelligence customers were promptly notified upon the discovery of the threat. Group-IB’s Computer Emergency Response Team (CERT-GIB) also issued a proactive notification to the Governmental National CERT of Vietnam (VNCERT) and continues its outreach campaign.

The malware was first spotted by Group-IB in June 2023. The company’s Threat Intelligence unit identified more than ten fake websites posing as Google Play Store pages and fake company websites. To appear more convincing, some fake websites include user reviews and the emblem of Vietnam.

Fake website distributing GoldDigger

Figure 1. Fake website distributing GoldDigger

These sites were designed to deceive users into downloading the malicious GoldDigger application, named after a specific Android activity, found within the APK file, called “GoldActivity”. Group-IB was not able to establish the initial vector, but the Trojan’s operators most likely distributed the links to these websites through messengers or traditional phishing. Group-IB detected two different strains of GoldDigger – one that impersonated a Vietnamese governmental portal and another imitating a local energy sector company.

After being installed and launched, GoldDigger requests access to Accessibility Service, an Android feature designed to assist users with disabilities by allowing apps to interact with each other and modify the user interface. By abusing this feature, the malware can monitor and manipulate the device’s functions.

By granting the Trojan access to Accessibility Service, the user unwittingly enables GoldDigger to extract sensitive information, such as passwords, intercept SMS messages, simulate user interactions, as well as to steal login credentials. The Trojan monitors events related to 51 targeted applications of Vietnamese financial organizations, as well as e-wallets and crypto apps. After capturing user input (such as logins and passwords), GoldDigger exfiltrates the data to command-and-control (C&C) servers.

GoldDigger profile infographic

Figure 2. GoldDigger profile

One notable feature of GoldDigger is that it uses Virbox Protector – a legitimate software that provides advanced obfuscation and encryption. Malware developers employ Virbox Protector to make it more challenging for cybersecurity researchers to analyze and reverse-engineer their malicious code and avoid detection by conventional anti-fraud solutions. Nonetheless, Group-IB’s Fraud Protection can effectively detect GoldDigger.

“However, Group-IB’s Threat Intelligence team found that, in addition to Vietnamese, the malware included language translations to Spanish and traditional Chinese. The cybercriminals may have plans to further extend GoldDigger’s reach to Spanish and Chinese-speaking countries in the near future. We continue the investigation into GoldDigger and will provide updates when they become available.”

Anh Le
Anh Le

Group-IB’s Business Development Manager in Vietnam

To minimize their risk of downloading banking Trojans such as GoldDigger, Group-IB recommends users always check for updates on their mobile devices, avoid downloading applications from sources outside of the Google Play Store, and check what permissions an application requests once it is downloaded. Companies seeking to safeguard their users from malware attacks might consider Group-IB’s Fraud Protection solution. It monitors user sessions by leveraging machine learning algorithms to identify suspicious behavior, the latest fraud techniques, unauthorized remote sessions, as well as the presence of malware, such as GoldDigger.

Try Group-IB Fraud Protection now!

Eliminate fraud across all digital channels in real time.

Request demo

About Group-IB

Established in 2003, Group-IB is a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime globally. Headquartered in Singapore, and with Digital Crime Resistance Centers in the Americas, Europe, Middle East and Africa, Central Asia, and the Asia-Pacific, Group-IB delivers predictive, intelligence-driven defense by analysing and neutralizing regional and country-specific cyber threats via its Unified Risk Platform, offering unparalleled defense through its industry-leading Cyber Fraud Intelligence Platform, Cloud Security Posture Management, Threat Intelligence, Fraud Protection, Digital Risk Protection, Managed Extended Detection and Response (XDR), Business Email Protection, and External Attack Surface Management solutions, catering to government, retail, healthcare, gaming, financial sectors, and beyond. Group-IB collaborates with international law enforcement agencies like INTERPOL, Europol, and AFRIPOL to fortify cybersecurity worldwide, and has been awarded by advisory agencies including Datos Insights, Gartner, Forrester, Frost & Sullivan, and KuppingerCole.

For more information, visit us at www.group-ib.com or connect with us on LinkedIn, X, Facebook, and Instagram.

Discover our podcasts to hear from leading voices on Masked Actors and Fraud Intel, where top cybersecurity experts share real-world experiences, emerging trends, and practical insights to help you stay one step ahead in the fight against cyber crime.