CYBERSECURITY

GoldFactory Launches Android Banking App‑Cloning Attack in Indonesia

GoldFactory Launches Android Banking App‑Cloning Attack in Indonesia

How the Work Profile Trick Works

A new phishing campaign has targeted Indonesian users by cloning popular banking apps on Android devices. The GoldFactory threat group exploited the Android Work Profile feature to deliver a malicious Trojan called Gigabud.

The attackers embedded the Trojan inside a legitimate‑looking banking app. When users installed the app, it created a separate work profile that bypassed the device’s standard security checks. The Trojan then harvested banking credentials and personal data, sending it back to the attackers. The operation began in early March and has already reached thousands of victims across the country.

Android Work Profiles let users separate work and personal data on the same device. GoldFactory used this feature to disguise their malware as a harmless app. The cloned app appears in the user’s app drawer, but it runs in a sandboxed environment that the device’s default security tools do not scrutinize. Because the app is signed with a legitimate certificate, it passes the Play Store’s safety checks.

What Makes Gigabud Dangerous?

Once installed, Gigabud opens a hidden background service that listens for login attempts. When a user enters their banking credentials, the service captures the data and forwards it to the attackers’ command‑and‑control server. The Trojan also records screenshots and keystrokes, giving the attackers a full view of the user’s activity.

Security researchers say the use of a work profile is a clever way to bypass standard anti‑malware solutions. „Most security apps only scan the personal profile,” notes Dr. Maya Suryani, a cybersecurity analyst. „By using a work profile, GoldFactory can hide its payload from the majority of detection engines.”

Gigabud is more than a simple credential‑stealer. It can also trigger additional downloads, such as a remote‑access trojan that provides the attackers with full control over the device. The malware can disable security settings, install root certificates, and create a backdoor for future attacks. The threat group has also been known to use the same technique to spread ransomware in other regions.

How Can Users Protect Themselves?

The attack’s impact is significant. Banking apps are trusted by millions of Indonesians, and a single compromised account can lead to substantial financial loss. Early estimates suggest that the campaign has already stolen over 200,000 user credentials, though the exact figure remains unclear.

Users should be wary of any banking app that requests unusual permissions, especially „draw over other apps” or „install unknown apps.” Installing apps only from the Google Play Store and keeping the OS and security software up to date are essential steps. If you notice unfamiliar apps or sudden battery drain, run a full device scan.

Looking Ahead: The Future of Mobile Banking Security

Financial institutions are urged to monitor for unusual login patterns and to notify customers promptly if suspicious activity is detected. Mobile banking apps should also adopt multi‑factor authentication to add an extra layer of protection.

The GoldFactory campaign illustrates how attackers adapt to platform features. As Android continues to evolve, security teams must anticipate new vectors like work profiles. Regulators may need to enforce stricter app vetting processes and require developers to disclose the use of enterprise features.

In the meantime, users must remain vigilant. „It’s a race between attackers and defenders,” says Dr. Suryani. „The best defense is a combination of technical safeguards and user awareness.”

Frequently Asked Questions

What is the Android Work Profile and why is it used in this attack? The Work Profile lets users separate work and personal data on a single device. Attackers use it to hide malicious code from standard security checks, making it harder for users and security tools to detect the threat.

How can I tell if my banking app has been cloned? Look for unfamiliar app names, extra permissions, or sudden changes in battery usage. If you see a new app that looks like your bank’s official app but behaves oddly, it may be a clone.

What should I do if I suspect my device is infected? Immediately uninstall the suspicious app, run a full security scan, and change all banking passwords from a trusted device. Contact your bank’s support for guidance and report the incident to local authorities.

Content written by Alexander Culafi for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment