You're on the Hook: The Evolution of Gigabud and GoldFactory's Expanding Arsenal
23 Oct 2025
Level 1 | Exhibition Hall, Sands Expo and Convention Centre
Darkweb, Cybercrime, Cyberwarfare
In the end of 2024, public attention to the infamous mobile threat Gigabud seems to have faded - but has the malware truly disappeared, or simply become better at hiding? In this talk, we will explore the evolving capabilities of the Gigabud mobile banking trojan and examine how its stealth mechanisms have improved over time.
As part of this investigation, we’ll discuss new trojans that enable Gigabud to operate more covertly in modern threat landscapes. We'll introduce two previously undocumented mobile malware families - SkyHook and FriHook - recently detected by Group-IB specialists. These trojans represent a significant expansion of the GoldFactory group’s toolkit, signaling a broader, more modular approach to mobile cybercrime.
Attendees will gain insights into emerging mobile malware tactics, detection challenges, and the shifting dynamics within financially motivated threat actor groups.
As part of this investigation, we’ll discuss new trojans that enable Gigabud to operate more covertly in modern threat landscapes. We'll introduce two previously undocumented mobile malware families - SkyHook and FriHook - recently detected by Group-IB specialists. These trojans represent a significant expansion of the GoldFactory group’s toolkit, signaling a broader, more modular approach to mobile cybercrime.
Attendees will gain insights into emerging mobile malware tactics, detection challenges, and the shifting dynamics within financially motivated threat actor groups.
