Indonesian Users Targeted by Sophisticated Android Banking App Cloning Scheme
Cybersecurity researchers have identified a coordinated campaign that is tricking Android users in Indonesia into installing counterfeit banking applications, a tactic that enables the delivery of the Gigabud Trojan through the Android Work Profile feature.
The operation, attributed to the GoldFactory threat group, leverages the Work Profile’s ability to separate personal and corporate data. By cloning legitimate banking apps and embedding malicious code, the attackers bypass typical security checks and install the Gigabud payload, which can capture credentials, generate fraudulent transactions, and exfiltrate sensitive information to remote servers.
In parallel, a separate malware family known as Mantax Otax has been observed spreading across the same ecosystem, employing its own infection chain that does not rely on the Work Profile. While the two strains appear to be run by distinct operators, both target the same user base, amplifying the overall risk to mobile banking customers.
Early estimates suggest that dozens of Indonesian users have fallen victim, with some reporting unauthorized debits and loss of personal data. Local banks have issued alerts urging customers to verify the authenticity of app downloads, and several financial institutions are reviewing their mobile security policies in response to the surge.
The episode underscores a broader trend in Southeast Asia, where the rapid adoption of mobile banking services has outpaced the development of robust security safeguards. Attackers are increasingly exploiting platform features such as Work Profile, which were originally designed to enhance enterprise security, turning them into vectors for sophisticated fraud.
Experts recommend that users download banking applications only from official app stores, enable two‑factor authentication, and regularly audit the permissions granted to installed apps. Meanwhile, Indonesian cybersecurity agencies are collaborating with global partners to trace the infrastructure behind GoldFactory and Mantax Otax, aiming to disrupt the networks before the campaign expands further.
Comments (0)
Be the first to comment.
Join the discussion