Indonesia has emerged as an early testing ground for a new Android banking malware technique that uses Google's Work Profile feature to help fraudsters evade banking security controls.
According to Group-IB, its researchers observed roughly 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia between February and July, resulting in nearly $1 million in estimated losses.
In research published Sept. 9, Group-IB described an Android banking malware technique used by the threat actor GoldFactory. GoldFactory is a Chinese-speaking threat group focused on mobile banking cyberattacks for financial gain. The ultimate goal is to clone a victim's banking app into an isolated environment where malware detections and fraud signals may not follow.
The malware used in this campaign is Gigabud, a banking Trojan targeting Android devices and active since 2022. It's used in attacks across Southeast Asia, South Asia, the Middle East, Africa, and Latin America. While the lure and infection context varies by region (attackers impersonated national airlines, tax authorities, and government portals), the malware generally grants an attacker immense influence over a target device. Once installed and granted the necessary permissions, the malware gives operators live remote control of the victim's phone.
Related:Fake Bahrain Alert App Deploys Android Surveillance Malware
What's significant about this latest research is that while researching Gigabud infections, Group-IB discovered the presence of an application called Vwork, a fork of the open source Android app-cloning application Shelter. Group-IB observed instances where Vwork would be installed within minutes of the initial Gigabud infection.
The research revealed that GoldFactory is deploying a new defense evasion technique through Android's Work Profile function, a feature intended for enterprise use that creates a separate, isolated space on the user's phone where apps are installed independently from one's personal profile.
Indonesia Targeted by Banking Trojans
Group-IB identified Vwork-compatible Gigabud samples targeting countries including Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, Philippines, Thailand, Turkey, and "a GCC [Gulf Cooperation Council] member state." But researchers Pavel Naumov and Bryan Karunachandra emphasized the impact on Indonesia in particular.
In one confirmed case, "the copy was a fake version of a real Indonesian bank's app," the researchers explained.
... continue reading