Find notable cyber news and cases, enriched with sources, timelines, and signals.

GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.

Campaign
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigger fraudulent transactions. The operation extends the reach of GoldFactory’s malware tooling and raises the risk of account takeover and real-time financial fraud.

Related Happenings

ToxicPanda 2.0 Android malware expands fraud capabilities

Malware Activity
H score29 First: 20.08.2026 13:38 Last: 20.08.2026 13:38 Sources 1

How related: Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally.

About this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...

WindRelay and SpyNote RAT Android NFC relay fraud activity

Malware Activity
H score33 First: 13.08.2026 01:22 Last: 13.08.2026 01:22 Sources 1

About this happening: The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity
H score20 First: 12.08.2026 17:30 Last: 12.08.2026 17:30 Sources 1

About this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...

RedWing Android bank-fraud malware rental service

Malware Activity
H score21 First: 07.07.2026 20:10 Last: 07.07.2026 20:10 Sources 1

About this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...

Grandoreiro and BTMOB banking trojan activity targeting Windows and Android

Malware Activity
H score25 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...

Timeline

  1. 20.08.2026 13:38 2 articles · 1h ago

    GoldDigger campaign spreads fake airline and shopping apps in South Africa and the U.K.

    Campaign Scope Update

    GoldDigger, first documented by Group-IB in October 2023 as capable of on-device fraud, is being used in a campaign that impersonates airline companies and shopping retailers to drive a massive infection in South Africa and the U.K. Victims who install the malicious apps are urged to grant accessibility permissions, which the malware abuses to inject input into banking apps, capture credentials with fake overlays, give the operator real-time screen access, and initiate fraudulent transactions.

    Show sources