# Indonesia Hit by Android Banking App-Cloning Campaign
Indonesian users face twin threats from sophisticated banking trojans deployed through app-cloning tactics that exploit core Android features. The GoldFactory threat group delivers the Gigabud Trojan by abusing the Android Work Profile, a legitimate feature designed for enterprise device management. Simultaneously, a separate malware family called Mantax Otax spreads through parallel infection vectors, targeting the same victim base.
Gigabud operates by creating a deceptive Work Profile that mirrors legitimate banking applications. When users install the trojan, attackers establish a sandboxed Android workspace that isolates malicious activity from standard device monitoring. This isolation layer complicates detection because users see legitimate-looking banking apps operating normally while the trojan runs credential-harvesting and transaction-interception routines in the background.
The threat actors behind GoldFactory demonstrate operational sophistication. They distribute Gigabud through compromised websites and phishing campaigns targeting Indonesian financial institutions. The malware captures login credentials, two-factor authentication codes, and one-time passwords before relaying stolen data to attacker command servers. Once authenticated, attackers drain victim accounts directly or resell credentials on underground forums.
Mantax Otax operates independently but pursues identical objectives. This malware family spreads through a different infection chain, potentially via malicious SMS links or social engineering. Mantax Otax also performs credential theft and transaction interception, though security researchers have documented distinct code signatures and C2 infrastructure separate from Gigabud operations.
Indonesia represents a high-value target. The nation hosts Southeast Asia's largest smartphone user base, exceeding 170 million active mobile devices. Digital banking adoption accelerated during the pandemic, creating dense populations of users unfamiliar with mobile security risks. Indonesian financial institutions process transactions valued in the hundreds of billions of dollars annually, making the region attractive to organized cybercriminal groups.
The Work Profile exploitation technique carries broader implications. Android Work Profile exists in virtually all modern Android devices and receives official vendor support from Google. Attackers weaponizing this legitimate feature bypass standard mobile antivirus detection because security tools struggle to distinguish malicious Work Profiles from authentic enterprise deployments. Organizations deploying Work Profiles for BYOD programs now face additional attack surface they did not previously acknowledge.
Organizations operating in Indonesia should implement device management policies restricting Work Profile installation to centrally managed devices only. Individual users should avoid sideloading applications and download banking apps exclusively from official Google Play Store listings. Indonesian banks should deploy out-of-band authentication for high-value transactions, requiring confirmation through SMS or call-center verification channels separate from the compromised device.
Mobile threat researchers report that Gigabud and Mantax Otax samples continue circulating. GoldFactory maintains active command infrastructure and deploys updated variants monthly. No public confirmation exists that either group faces law enforcement action, suggesting both operations remain operational. Indonesian financial regulators have not issued sector-wide advisories recommending specific technical controls.
The campaign underscores how legacy Android security assumptions no longer apply. Work Profile abuse demonstrates that privileged features intended for legitimate purposes become high-value attack vectors when threat actors gain access. Indonesia's explosive mobile growth creates opportunity for attackers while security awareness among consumers lags infrastructure deployment.
