The GoldFactory threat group is leveraging Android's Work Profile feature to deploy the Gigabud Trojan, enabling them to clone banking apps and bypass security controls in Indonesia.

  • GoldFactory group uses the 'Gigabud' Trojan to target Android banking users.
  • Android's Work Profile feature is exploited to create an isolated environment for app cloning.
  • Approximately 1,469 devices in Indonesia were compromised, leading to ~$1 million in losses.
  • Vwork, a fork of the Shelter app, is used to facilitate the cloning process.

Indonesia has become a primary testing ground for a sophisticated Android banking malware technique. According to Group-IB, fraudsters are now exploiting Google's Work Profile feature—originally designed for enterprise separation of personal and professional data—to evade banking security controls and steal funds.

The campaign is orchestrated by GoldFactory, a Chinese-speaking threat actor focused on financial gain through mobile attacks. The primary tool used is the Gigabud Trojan, which has been active since 2022 across Southeast Asia, the Middle East, and Latin America. Once the malware gains accessibility permissions, it grants the operators full remote control over the victim's device.

The Mechanics of App-Cloning

The breakthrough in this attack is the deployment of Vwork, a modified version of the open-source app-cloning tool 'Shelter'. After the initial Gigabud infection, Vwork is installed to create a separate Work Profile. The malware then clones the victim's legitimate banking app into this sandboxed environment. Because the Work Profile is isolated, security tools monitoring the personal profile often fail to detect the malicious activity occurring within the work profile.

Why This Matters

BozokMedia analysis shows that this represents a paradigm shift in evasion tactics. Most fraud detection systems rely on specific app instances or profile signals. By separating the malware detection (which triggers in the personal profile) from the fraudulent transaction (which occurs in the work profile), attackers effectively break the link that would normally alert a bank to a compromise. This allows them to 'cash out' while the user remains unaware, often hidden by a black screen overlay.

"Mobile banking malware is a global threat, and attackers concentrate activity wherever mobile financial services are widely used and social-engineering can be localized."

While Indonesia is the current hotspot, Group-IB identified compatible samples targeting Brazil, Colombia, Egypt, and several GCC member states. Furthermore, the simultaneous emergence of Mantax Otax—another aggressive Trojan linked to Indonesian actors—highlights the region's vulnerability due to high mobile banking penetration.

Feature Standard Banking Trojan GoldFactory Campaign
Evasion Method Obfuscation/Encryption OS-level Profile Isolation
Execution Direct App Overlay Cloned App in Work Profile
Detection Gap Signature-based detection Profile-based signal disconnect
Did You Know?: The Android Work Profile was designed to allow IT administrators to manage corporate apps without accessing a user's private photos or messages.

Frequently Asked Questions

Q1: How can I tell if my phone has been infected by this campaign?
Check for a 'Work Profile' tab in your app drawer that you didn't set up, or look for duplicate banking apps on your device.

Q2: What is the best way to prevent such attacks?
Avoid granting 'Accessibility' permissions to apps from unknown sources and never install APKs from third-party websites.