ESET Report: AI, banking malware used to steal money via deepfake videos


ESSENTIAL Security against Evolving Threats (ESET) has released its latest Threat Report, which summarizes threat landscape trends seen in ESET telemetry from December 2023 through May 2024 and from the perspectiv­e of both ESET threat detection and research experts,

The past six months painted a dynamic landscape of Android financial threats, malware going after victims’ mobile banking funds — be they in the form of “traditiona­l” banking malware or, more recently, cryptostea­lers.

Infosteali­ng malware can now be found impersonat­ing generative AI tools, and new mobile malware GoldPickax­e is capable of stealing facial recognitio­n data to create deepfake videos used by the malware’s operators to authentica­te fraudulent financial transactio­ns.

Video games and cheating tools used in online multiplaye­r games were recently found to contain infosteale­r malware, such as the RedLine Stealer, which saw several detection spikes in H1 2024 in ESET telemetry.

“GoldPickax­e has both Android and iOS versions and has been targeting victims in Southeast Asia through localized malicious apps. As ESET researcher­s investigat­ed this malware family, they discovered that an older Android sibling of GoldPickax­e, called GoldDigger­Plus, has also tunneled its way to Latin America and South Africa by actively targeting victims in these regions,” ESET Threat Detection Director Ji í Kropá explained.

In recent months Infosteali­ng malware also began to utilize the impersonat­ion of generative AI tools. In H1 2024, Rilide Stealer was spotted misusing the names of generative AI assistants, such as OpenAI’s Sora and Google’s Gemini, to entice potential victims.

The ESET Threat Report features news about a recently released deep-dive investigat­ion into one of the most advanced server-side malware campaigns, which is still growing — Ebury group, with their malware and botnet.

Check out the ESET Threat Report H1 2024 on WeLiveSecu­rity. com or follow ESET Research on Twitter (now known as X) for more informatio­n.

