Indonesia Becomes Testing Ground for Sophisticated Android Banking Malware Technique
A new wave of targeted attacks is sweeping through Indonesia, exploiting a vulnerability in Google’s Android Work Profile feature to deliver malware that can evade banking security controls. The threat group behind this campaign, known as GoldFactory, has been observed using the Gigabud Trojan to clone victims’ banking apps and steal sensitive information.
The impact on Indonesia has been significant, with Group-IB researchers estimating that nearly $1 million in losses have resulted from the attacks between February and July of this year. The compromised devices and potentially compromised logins total around 1,469 and 1,281 respectively, highlighting the scale of the issue.
At its core, the malware technique used by GoldFactory relies on the Android Work Profile feature, which was intended for enterprise use but has been co-opted for malicious purposes. By creating a separate, isolated space on the user’s phone, the attackers can install apps independently from their personal profile and evade detection by banking security controls.
The researchers at Group-IB observed that the malware used in these attacks, known as Gigabud, is active since 2022 and has been targeting Android devices across Southeast Asia, South Asia, the Middle East, Africa, and Latin America. The attackers use a variety of lures to infect victims’ phones, including impersonating national airlines, tax authorities, and government portals.
What’s particularly concerning about this campaign is that it involves a new defense evasion technique, where the malware creates a work profile and clones the victim’s banking app into a sandboxed environment. This allows the attackers to carry out transactions directly on the victim’s phone while evading detection by security controls.
The researchers also discovered an application called Vwork, a fork of the open-source Android app-cloning application Shelter, which is installed within minutes of the initial Gigabud infection. This suggests that GoldFactory is using this technique not only to evade detection but also to create a more convincing and persistent presence on the victim’s device.
The impact on Indonesia has been significant, with confirmed cases of fake banking apps being cloned onto victims’ phones. Nico Chiaraviglio, chief scientist at Zimperium, notes that Indonesia’s large mobile population and widespread use of mobile banking services make it an attractive target for this kind of malware.
As the threat landscape continues to evolve, it’s essential for users in Indonesia and beyond to be aware of these sophisticated attacks and take steps to protect themselves. This includes being cautious when receiving unsolicited messages or calls, keeping software up-to-date, and using robust security controls to detect and prevent malware infections. By staying vigilant and informed, we can mitigate the impact of these targeted attacks and safeguard our digital assets.
Source: Dark Reading — 2026-09-11