Indonesia Hit by Android Banking App-Cloning Campaign

Indonesia has become an early testing ground for a sophisticated Android malware campaign, with threat actors exploiting the Google Work Profile feature to evade banking security controls and siphon off millions of dollars from unsuspecting victims. The attack, which has already compromised over 1,469 devices and 1,281 potentially vulnerable logins in Indonesia, is a stark reminder that mobile banking cyberattacks are becoming increasingly common and sophisticated.

The malware at the heart of this campaign is called Gigabud, a banking Trojan that has been active since 2022. It’s used to clone a victim’s banking app into an isolated environment where malware detections and fraud signals may not follow, allowing attackers to carry out transactions directly on the victim’s phone while evading detection. The ultimate goal of this campaign is financial gain, with threat actors targeting countries across Southeast Asia, South Asia, the Middle East, Africa, and Latin America.

What sets this attack apart from others is its use of Android’s Work Profile feature, a security tool designed for enterprise use that creates a separate, isolated space on the user’s phone where apps are installed independently from their personal profile. By exploiting this feature, attackers can evade traditional malware detection methods and create a sandboxed environment where they can clone banking apps without being detected.

The attack has been linked to a Chinese-speaking threat group called GoldFactory, which has been focused on mobile banking cyberattacks for financial gain. According to researchers at Group-IB, the threat actors behind this campaign have also deployed an application called Vwork, a fork of the open-source Android app-cloning application Shelter. This allows them to create a work profile and clone a banking application into that sandboxed environment in a matter of minutes.

But Indonesia is not alone in facing this threat. Mobile banking malware is a global issue, with attackers targeting countries where mobile financial services are widely used and social-engineering campaigns can be effectively localized. As Nico Chiaraviglio, chief scientist at Zimperium, notes, “Indonesia’s large, highly mobile population and widespread use of mobile banking, digital payment, messaging platforms, and Android devices make it an attractive target for this kind of malware.”

The implications of this attack are clear: mobile banking users must be vigilant in protecting their devices from malware and phishing attacks. This means being cautious when clicking on links or downloading apps, especially if they come from unknown sources. It also highlights the importance of keeping software up to date and using robust security measures such as two-factor authentication.

In conclusion, this campaign serves as a stark reminder that mobile banking cyberattacks are becoming increasingly sophisticated and widespread. As attackers continue to exploit vulnerabilities in Android devices and evade traditional malware detection methods, it’s essential for users to stay informed and take steps to protect themselves from these threats. By being aware of the risks and taking simple precautions, we can all do our part in preventing these types of attacks and protecting our financial information online.


Source: Dark Reading — 2026-09-11