Skip to content
Tech News
← Back to articles

Indonesia Hit by Android Banking App-Cloning Campaign

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

Group-IB says the Chinese-speaking GoldFactory group is abusing Android's enterprise Work Profile feature to clone victims' banking apps into an isolated container where fraud and malware detection signals don't follow. Roughly 1,469 compromised devices and nearly $1 million in losses were tracked in Indonesia between February and July, suggesting the country is a testing ground before wider rollout. It shows attackers repurposing legitimate OS and open source tools to defeat bank-side security controls.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — When Android banking Trojans like Gigabud can hijack apps and intercept codes on the phone itself, a hardware key keeps the login secret off the device entirely. The YubiKey 5 NFC taps against a phone or plugs into USB-A to confirm sign-ins for accounts that support FIDO2/U2F, so a cloned app can't just replay your credentials.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Indonesia has emerged as an early testing ground for a new Android banking malware technique that uses Google's Work Profile feature to help fraudsters evade banking security controls.

According to Group-IB, its researchers observed roughly 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia between February and July, resulting in nearly $1 million in estimated losses.

In research published Sept. 9, Group-IB described an Android banking malware technique used by the threat actor GoldFactory. GoldFactory is a Chinese-speaking threat group focused on mobile banking cyberattacks for financial gain. The ultimate goal is to clone a victim's banking app into an isolated environment where malware detections and fraud signals may not follow.

The malware used in this campaign is Gigabud, a banking Trojan targeting Android devices and active since 2022. It's used in attacks across Southeast Asia, South Asia, the Middle East, Africa, and Latin America. While the lure and infection context varies by region (attackers impersonated national airlines, tax authorities, and government portals), the malware generally grants an attacker immense influence over a target device. Once installed and granted the necessary permissions, the malware gives operators live remote control of the victim's phone.

Related:Fake Bahrain Alert App Deploys Android Surveillance Malware

What's significant about this latest research is that while researching Gigabud infections, Group-IB discovered the presence of an application called Vwork, a fork of the open source Android app-cloning application Shelter. Group-IB observed instances where Vwork would be installed within minutes of the initial Gigabud infection.

The research revealed that GoldFactory is deploying a new defense evasion technique through Android's Work Profile function, a feature intended for enterprise use that creates a separate, isolated space on the user's phone where apps are installed independently from one's personal profile.

Indonesia Targeted by Banking Trojans

Group-IB identified Vwork-compatible Gigabud samples targeting countries including Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, Philippines, Thailand, Turkey, and "a GCC [Gulf Cooperation Council] member state." But researchers Pavel Naumov and Bryan Karunachandra emphasized the impact on Indonesia in particular.

In one confirmed case, "the copy was a fake version of a real Indonesian bank's app," the researchers explained.

... continue reading