Fake Banking Apps Target Android Users in Indonesia Cloning Campaign
Security researchers have identified a campaign targeting Android users in Indonesia, where the threat group GoldFactory is abusing the Android Work Profile feature to deliver a banking trojan known as Gigabud. This feature, designed to separate personal and work apps, is being manipulated to hide malicious software and slip past standard security checks on infected devices.
A separate malware family, referred to as Mantax Otax, is also being distributed as part of related activity, though it operates independently of the GoldFactory campaign. Both threats appear focused on compromising banking credentials and financial information from victims, a pattern consistent with wider trends in mobile banking malware across the region.
While the campaign is currently concentrated in Indonesia, Australian small businesses with staff or customers using Android devices for banking should stay alert, as such techniques often spread to other markets once proven effective.