GoldFactory Deploys Gigabud Trojan to Clone Indonesian Banking Apps
Cybersecurity researchers have identified an active Android banking malware campaign targeting users in Indonesia, orchestrated by the financially motivated threat group GoldFactory. The group is exploiting Android's Work Profile feature—a legitimate enterprise management tool designed to separate corporate and personal data on a single device—to disguise malicious applications as trusted banking apps. Once installed, the Gigabud Trojan overlays fraudulent login screens on legitimate financial applications, harvesting credentials in real time and enabling account takeover attacks.
GoldFactory's operators have refined their social engineering tactics to distribute the malware through sideloaded APK files disguised as productivity tools and banking utilities. By abusing Work Profile permissions, the trojan gains elevated access to device resources while evading casual user suspicion. Separately, the Mantax Otax malware family continues to circulate in the region through its own distribution channels, compounding the threat landscape for Indonesian mobile banking customers.
The campaign underscores a growing trend of threat actors abusing legitimate OS features rather than relying solely on exploit chains. Users sidestepping official app stores remain the primary infection vector, though the Work Profile abuse introduces new detection challenges for mobile security tools.
Readers concerned about credential exposure can verify their accounts using the email breach checker and strengthen authentication with the password checker. A full privacy checkup is recommended for users in the region who may have installed unverified applications in recent months.