Threat Intelligence

Fake Banking Apps Target Android Users in Indonesia Cloning Campaign

Dark Reading · 11 Sept 2026
Key Takeaway Only install banking apps from official app stores, keep Android devices updated, and be cautious of any app requesting unusual profile or admin permissions.

Security researchers have identified a campaign targeting Android users in Indonesia, where the threat group GoldFactory is abusing the Android Work Profile feature to deliver a banking trojan known as Gigabud. This feature, designed to separate personal and work apps, is being manipulated to hide malicious software and slip past standard security checks on infected devices.

A separate malware family, referred to as Mantax Otax, is also being distributed as part of related activity, though it operates independently of the GoldFactory campaign. Both threats appear focused on compromising banking credentials and financial information from victims, a pattern consistent with wider trends in mobile banking malware across the region.

While the campaign is currently concentrated in Indonesia, Australian small businesses with staff or customers using Android devices for banking should stay alert, as such techniques often spread to other markets once proven effective.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.