GoldDigger is an Android banking trojan attributed to the GoldFactory threat actor. It uses the dpt-shell packer for obfuscation and evasion, and performs on-device fraud by injecting input into banking apps. Recent campaigns impersonate airlines and retailers, causing infections in South Africa and the U.K.