HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Android Banking App‑Cloning Campaign Targets Indonesian Users via Work Profile Exploit

GoldFactory is abusing Android Work Profile to deliver the Gigabud Trojan, cloning banking apps and stealing credentials from Indonesian users. The campaign highlights the need for robust mobile access‑control evidence to satisfy audit‑readiness requirements.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
darkreading.com

Android Banking App‑Cloning Campaign Targets Indonesian Users via Work Profile Exploit

What Happened — The GoldFactory threat group is abusing the Android Work Profile feature to distribute the Gigabud Trojan, which clones legitimate banking applications and harvests credentials. A separate actor, Mantax Otax, is running a parallel campaign distributing its own banking‑trojan payloads.

Why It Matters for Trust & Control Assurance

  • This attack demonstrates how a mis‑managed mobile‑device‑management (MDM) environment can become a conduit for credential theft, a scenario continuous control‑assurance programs are built to detect and evidence.
  • Demonstrable evidence of device‑profile segregation, app‑allow‑list enforcement, and credential‑access monitoring satisfies a single control objective that maps to many frameworks (e.g., NIST CSF 2.0 Identity Management).
  • Verisq’s Access Controls capability provides the audit‑ready logs and policy‑validation evidence needed to prove that your organization enforces strict app‑origin controls and monitors privileged‑access attempts on mobile devices.

Who Is Affected – Financial services firms operating in Indonesia and any organization that allows employees or customers to use Android Work Profile for banking or payment applications.

Recommended Actions

  • Review and tighten MDM policies: enforce app‑signing verification, restrict installation sources, and isolate work profiles from personal apps.
  • Deploy continuous monitoring of credential‑access events on mobile endpoints and integrate logs into a central Trust Center for audit readiness.
  • Conduct targeted security‑awareness training for users on the risks of cloned banking apps and how to verify authentic app signatures.

Source: Dark Reading

Technical Notes

  • Attack vector: Exploitation of Android Work Profile to deliver the Gigabud Trojan; separate Mantax Otax payloads use similar cloning techniques.
  • Malware: Gigabud Trojan (banking‑credential stealer) and Mantax Otax trojan.
  • Data types at risk: Banking credentials, OTP tokens, personal identification numbers.

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →