Search
Close this search box.
Search
Close this search box.

iOS Breakthrough: First Trojan Steals Facial Recognition Data to Hack Bank Accounts

First iOS Trojan Steals Facial Recognition Data

Many individuals choose the best iPhones over Android devices primarily because of security reasons. It appears that the situation may be shifting with the recent discovery of a banking trojan specifically aimed at iPhone users.

A recent report from Group-IB reveals that the Android trojan GoldDigger has been updated with enhanced features, allowing it to more effectively empty victims’ bank accounts. Discovered in October, a new variation of the trojan has been named GoldPickaxe, tailored for Android and iOS devices.

After being installed on a smartphone, GoldPickaxe is capable of gathering facial recognition data, identity documents, and intercepted text messages. This information is then used to facilitate the unauthorized transfer of funds from banking and financial applications. Unfortunately, the biometric data is later utilized to generate AI deepfakes that mimic victims and gain access to their bank accounts.

Currently, the GoldPickaxe trojan is specifically targeting victims in Vietnam and Thailand. Yet, like other malware campaigns, if this one is successful, the cybercriminals could potentially broaden their operations to target iPhone and Android users in the U.S., Canada, and other English-speaking nations.

For those with an iPhone or an Android device, here’s important information about a new banking trojan and tips to ensure iPhone users stay protected, especially since they may be unfamiliar with this type of threat.

TestFlight to Mobile Device Management

Android banking trojans are usually spread through malicious apps and phishing attacks, but it’s harder to get a trojan onto an iPhone because Apple’s ecosystem is more closed-off compared to Google’s. Once again, hackers have managed to find a way.

At the start of this malware campaign, the individuals responsible used Apple’s mobile application testing platform TestFlight to spread the GoldPixaxe.IOS trojan. Getting a malicious app onto Apple’s App Store is quite challenging, but it can be done by exploiting the iPhone maker’s TestFlight program. Initially successful during the campaign, the removal of the malicious app from TestFlight prompted the hackers to devise a more advanced method for spreading their iOS trojan.

After losing TestFlight access, the hackers convinced their victims to install a Mobile Device Management (MDM) profile through social engineering tactics. If you’re not familiar with it, MDM is a methodology and set of tools used by a business’ IT department to manage company phones, computers, and other devices. When a victim fell for the new tactic, the hackers gained complete control over their iPhone.

Group-IB reports that one threat actor known as GoldFactory has created both versions of the GoldPickaxe banking trojan. After publishing their initial research, the company’s security researchers found a new variant of the malware called GoldDiggerPlus. However, with the top streaming services, the addition of “plus” now allows hackers to make real-time calls to their victims on an infected device.

Considering the potential profitability of a banking trojan such as GoldDigger or GoldPickaxe, particularly when it can target both iPhones and Android phones, it is probable that we will continue to hear about this malware and the hackers responsible for it.

How to Protect iPhone from Malware?

What steps do you take now that your iPhone is susceptible to malware, similar to an Android phone? Thankfully, Apple is probably already aware of this trojan and is working on a solution. Here are some extra suggestions to assist in safeguarding you and your devices.

Firstly, avoid installing any apps via TestFlight. It’s simple to steer clear of this situation. You need to download TestFlight before installing any unapproved apps on your iPhone, as per Apple’s support document. Not many individuals have a personal connection with an app developer who might seek their assistance. Therefore, it’s advisable to decline if someone requests that you install TestFlight on your iPhone or iPad. Similarly, you can add an MDM profile to your iPhone. Only your employer should request this, and only if you have a company-issued iPhone.

Although there is no direct counterpart to the top Android antivirus apps for iOS because of Apple’s limitations on malware scanning apps, there is a solution. Intego Mac Internet Security X9 or Intego Mac Premium Bundle X9 are considered two of the top Mac antivirus software solutions. They allow you to perform malware scans on an iPhone or iPad, but only when the device is connected to a Mac using a USB cable. If you’re concerned about malware on your iPhone, this feature alone could justify signing up for either product.

If you are more vulnerable than other iPhone users, it could be a good idea to activate Lockdown Mode. This feature may limit the functionality of some apps. It’s important to activate Apple’s Stolen Device Protection to feel more secure in case your iPhone is stolen.

Malware targeting iPhones has become a real threat, but by following good cybersecurity practices and avoiding unnecessary risks, you can keep yourself and your devices protected from hackers.


Subscribe to Our Newsletter

Related Articles

Top Trending

Hannah waddingham Jason Sudeikis ted lasso
Hannah Waddingham and Jason Sudeikis Relationships During Ted Lasso
Elon Musk's Fascination with OpenAI
Elon Musk Calls Off India Trip Due to Tesla's Challenges in the US
Nurys Cooley
The Empowering Work of Nurys Cooley: A Trailblazer for Women's Rights
swedish movies on netflix
Discover The Top Swedish Movies on Netflix to Watch Right Now [2024 Updates]
Elon Musk Tesla New Challenge Approaching
Elon Musk's Latest Hurdle: A Major Challenge Approaches Tesla

LIFESTYLE

Most Expensive Handbags for Women in the World
Elegance Redefined: 10 Most Expensive Handbags for Women in the World
Gift Ideas for Men
10 Thoughtful and Unique Gift Ideas for Men Who Have Everything
pohela boishakh 2024
Pohela Boishakh: Celebrating Bengali Culture and Heritage Festivities
Korean Beauty Secrets
10 Korean Beauty Secrets for Youthful Energy: Stay Young & Vibrant
Ancient Philosophers Guide to Happiness
Unlocking Happiness: Timeless Lessons from Ancient Philosophers

Entertainment

Hannah waddingham Jason Sudeikis ted lasso
Hannah Waddingham and Jason Sudeikis Relationships During Ted Lasso
swedish movies on netflix
Discover The Top Swedish Movies on Netflix to Watch Right Now [2024 Updates]
Under the Bridge Hulu Real Case Series
Under the Bridge: Hulu's Latest Must-Watch Series Explores a Real Case
dickey betts dies at 80
Dickey Betts, Allman Brothers Band Co-Founder, Dies at 80
transformers one trailer launch
Transformers One Launches Trailer From Space! The Movie Arrives in September

GAMING

Mobile Sports Betting Apps in the US
The Surge of Mobile Sports Betting Apps in the US, Benefits and Drawbacks
Pokemon Go Updates Avatars Maps Photos
Pokemon Go Update: New Changes to Avatars, Map, Photos & More
Apple's First Approved iPhone Emulator Launches
Apple's First Approved iPhone Emulator Launches, Then Gets Removed
Prime Gaming
Is 2024 the Year Prime Gaming Takes Off?
Online Games for Stress Relief
Finding Calm in the Click: A Comparative Look at Online Games for Stress Relief

BUSINESS

Elon Musk's Fascination with OpenAI
Elon Musk Calls Off India Trip Due to Tesla's Challenges in the US
Nurys Cooley
The Empowering Work of Nurys Cooley: A Trailblazer for Women's Rights
Elon Musk India Tour 2024 Itinerary
Elon Musk Historic India Visit 2024 Itinerary: The Agendas So Far
Douglas Palermo
Financial Status of Douglas Palermo After His Bankruptcy [2024 Update]
Choose the Right ERP System
How to Choose the Right ERP System for Your Business?

TECHNOLOGY

Microsoft Vasa 1 AI Animates Images to Move Speak
Microsoft's VASA-1 AI Brings Any Image to Life with Movement and Speech
Nokia Magic Max 5G
Nokia Magic Max 5G: A New Era of Smartphones Begins
Google Merges Android Chrome Hardware
Google Unifies Android, Chrome, and Hardware Divisions
electric mini car for adults
Electric Mini Car for Adults in 2024: Affordable and Stylish Options
How to Use Technology Mindfully
How to Use Technology Mindfully: Essential Tips for Balanced Tech

HEALTH

A Comprehensive Experience with Dr. Aravind Bhateja
A Comprehensive Experience at Sparsh Hospital in Bangalore with Dr. Aravind Bhateja
why veterans choose Out of Town Rehab
Finding Freedom: Why Veterans Should Opt for Out-of-Town Rehab?
Rock Hudson Last Days
Rock Hudson's Last Days: The Untold Story of His Final Moments
Best Stress Relief for Each Zodiac Sign
Relaxation by the Stars: Best Stress Relief for Each Zodiac Sign
Covid 19 No Link Asthma Risk Study
COVID-19 Does Not Raise Asthma Risk, Researchers Confirm