Indonesia Hit by Android Banking App-Cloning Campaign
A new Android banking malware campaign targeting Indonesia utilizes a clever evasion tactic leveraging Google's Work Profile feature. The threat actor, GoldFactory (a Chinese-speaking group), employs the Gigabud Trojan, alongside a fork of the open-source Vwork application, to clone banking apps into isolated work profiles, bypassing fraud detection systems and facilitating unauthorized transactions. This campaign has resulted in approximately $1 million in estimated losses in Indonesia and is part of a broader global trend of mobile banking malware targeting regions with high mobile banking adoption.
Indonesia is experiencing a surge in Android banking malware attacks, primarily driven by a sophisticated technique exploiting Google's Work Profile feature. Group-IB researchers have identified GoldFactory, a Chinese-speaking threat group, utilizing the Gigabud Trojan to deliver the malware. Gigabud targets Android devices and has been active since 2022, spreading across Southeast Asia, South Asia, the Middle East, Africa, and Latin America.
What’s significant is that GoldFactory is employing a new defense evasion tactic by leveraging Work Profile, a Google feature designed for enterprise use that creates a separate, isolated space on the user’s phone. The malware uses Vwork, a fork of the open-source Shelter application, to clone a victim’s banking app into this isolated profile. Once installed, Vwork doesn’t have its own command-and-control (C2) functionality, instead relying on Gigabud to relay commands.
This allows operators to carry out transactions directly on the victim’s phone while a black screen hides the activity, effectively bypassing fraud protection controls. The cloned environment avoids triggering fraud detection alerts in the victim’s personal profile, even if malware is detected there. Group-IB’s research indicates that this campaign has resulted in approximately $1 million in estimated losses in Indonesia, with Vwork-compatible Gigabud samples targeting countries including Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, Philippines, Thailand, Turkey, and “a GCC [Gulf Cooperation Council] member state.”
Nico Chiaraviglio, chief scientist at Zimperium, notes that Indonesia is a prime target due to its large mobile population, widespread mobile banking, digital payment, messaging platform, and Android device usage. He emphasizes that mobile banking malware is a global threat, and attackers concentrate activity in regions with high mobile financial services adoption. Group-IB recommends users look out for identical banking application installations across profiles, accessibility access enabled for apps that should not require it, or any unexpected app installation from a non-legitimate source being installed shortly following a previous phone install.
