Close Menu
The Daily PostingThe Daily Posting
  • Home
  • Android
  • Business
  • IPhone
    • Lifestyle
  • Politics
  • Europe
  • Science
    • Top Post
  • USA
  • World
Facebook X (Twitter) Instagram
Trending
  • Jennifer Lopez and Ben Affleck reveal summer plans after Europe trip
  • T20 World Cup: Quiet contributions from Akshar Patel, Kuldeep Yadav and Ravindra Jadeja justify Rohit Sharma’s spin vision | Cricket News
  • The impact of a sedentary lifestyle on health
  • Bartok: The World of Lilette
  • Economists say the sharp rise in the U.S. budget deficit will put a strain on Americans’ incomes
  • Our Times: Williams memorial unveiled on July 4th | Lifestyle
  • Heatwaves in Europe are becoming more dangerous: what it means for travelers
  • Christian Science speaker to visit Chatauqua Institute Sunday | News, Sports, Jobs
Facebook X (Twitter) Instagram
The Daily PostingThe Daily Posting
  • Home
  • Android
  • Business
  • IPhone
    • Lifestyle
  • Politics
  • Europe
  • Science
    • Top Post
  • USA
  • World
The Daily PostingThe Daily Posting
Android

Alarming Android and iOS GoldPickaxe malware trying to steal your face

thedailyposting.comBy thedailyposting.comFebruary 15, 2024No Comments

[ad_1]

iPhone camera

We’ve seen malware that attempts to steal files, money, and even personal information before, but a new mobile malware called Gold Pickaxe goes one step further. This nasty little software is active on both Android and iOS and steals the faces of its victims. Security researchers have warned that the malware could be used to create deepfake versions of victims and commit financial fraud.

This new malware was discovered by security firm Group-IB and is associated with a Chinese threat actor known as GoldFactory. The group’s latest effort builds on previous malware campaigns such as GoldDigger, GoldDiggerPlus, and GoldKefu. Although the new GoldPickaxe is primarily operational in the Asia-Pacific region, particularly Thailand, Group-IB emphasizes that the same technology can be applied anywhere.

GoldPickaxe does not exploit any security flaws in Android or iOS. This is a good old social engineering attack. Malware operators begin by sending messages on messaging apps like Line, claiming to represent a government agency. Victims using Android smartphones are directed to download an app from a website that pretends to be Google Play Store. For iPhone users, the Apple TestFlight profile was initially used to install the malware, but after Apple removed the app, attackers used malicious mobile device management (MDM) to gain control of the device. ) I switched to the profile.

At this point, victims using the fake government app are asked to provide mountains of personal data. This app can capture images of victims’ IDs and steal recently captured photos. It also asks users to take a video of their face with their phone’s camera. The interface is similar to a legitimate facial recognition unlock system, but the video is sent directly to the malware’s command and control server. The Android client has a few more features, such as SMS access, thanks to the more permissive nature of the platform.

face capture

GoldPickaxe could enable significant financial theft, as some financial institutions, especially those in South Asia, have started requiring biometrics for large transactions. Thai police reportedly confirmed that the attackers used these stolen faces to transfer funds from the victims’ accounts. Facial recognition systems that don’t use 3D data are surprisingly easy to fool.

Importantly, the malware cannot access biometric data on your phone, Bleeping Computer reports. That data is encrypted and can only be stolen through a critical vulnerability. This app is all about fooling people. Unfortunately, he seems to be pretty good at it.

[ad_2]

Source link

thedailyposting.com
  • Website

Related Posts

Qualcomm wants to make it easier for phone makers to issue Android updates

June 28, 2024

Qualcomm wants to make Android updates easier for OEMs

June 28, 2024

What’s new in the June 2024 Google system update for Android

June 28, 2024
Leave A Reply Cancel Reply

ads
© 2025 thedailyposting. Designed by thedailyposting.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms of Service
  • Advertise with Us
  • 1711155001.38
  • xtw183871351
  • 1711198661.96
  • xtw18387e4df
  • 1711246166.83
  • xtw1838741a9
  • 1711297158.04
  • xtw183870dc6
  • 1711365188.39
  • xtw183879911
  • 1711458621.62
  • xtw183874e29
  • 1711522190.64
  • xtw18387be76
  • 1711635077.58
  • xtw183874e27
  • 1711714028.74
  • xtw1838754ad
  • 1711793634.63
  • xtw183873b1e
  • 1711873287.71
  • xtw18387a946
  • 1711952126.28
  • xtw183873d99
  • 1712132776.67
  • xtw183875fe9
  • 1712201530.51
  • xtw1838743c5
  • 1712261945.28
  • xtw1838783be
  • 1712334324.07
  • xtw183873bb0
  • 1712401644.34
  • xtw183875eec
  • 1712468158.74
  • xtw18387760f
  • 1712534919.1
  • xtw183876b5c
  • 1712590059.33
  • xtw18387aa85
  • 1712647858.45
  • xtw18387da62
  • 1712898798.94
  • xtw1838737c0
  • 1712953686.67
  • xtw1838795b7
  • 1713008581.31
  • xtw18387ae6a
  • 1713063246.27
  • xtw183879b3c
  • 1713116334.31
  • xtw183872b3a
  • 1713169981.74
  • xtw18387bf0d
  • 1713224008.61
  • xtw183873807
  • 1713277771.7
  • xtw183872845
  • 1713329335.4
  • xtw183874890
  • 1716105960.56
  • xtw183870dd9
  • 1716140543.34
  • xtw18387691b

Type above and press Enter to search. Press Esc to cancel.