Android Banking App‑Cloning Campaign Targets Indonesian Users via Work Profile Exploit
What Happened — The GoldFactory threat group is abusing the Android Work Profile feature to distribute the Gigabud Trojan, which clones legitimate banking applications and harvests credentials. A separate actor, Mantax Otax, is running a parallel campaign distributing its own banking‑trojan payloads.
Why It Matters for Trust & Control Assurance
- This attack demonstrates how a mis‑managed mobile‑device‑management (MDM) environment can become a conduit for credential theft, a scenario continuous control‑assurance programs are built to detect and evidence.
- Demonstrable evidence of device‑profile segregation, app‑allow‑list enforcement, and credential‑access monitoring satisfies a single control objective that maps to many frameworks (e.g., NIST CSF 2.0 Identity Management).
- Verisq’s Access Controls capability provides the audit‑ready logs and policy‑validation evidence needed to prove that your organization enforces strict app‑origin controls and monitors privileged‑access attempts on mobile devices.
Who Is Affected – Financial services firms operating in Indonesia and any organization that allows employees or customers to use Android Work Profile for banking or payment applications.
Recommended Actions
- Review and tighten MDM policies: enforce app‑signing verification, restrict installation sources, and isolate work profiles from personal apps.
- Deploy continuous monitoring of credential‑access events on mobile endpoints and integrate logs into a central Trust Center for audit readiness.
- Conduct targeted security‑awareness training for users on the risks of cloned banking apps and how to verify authentic app signatures.
Source: Dark Reading
Technical Notes
- Attack vector: Exploitation of Android Work Profile to deliver the Gigabud Trojan; separate Mantax Otax payloads use similar cloning techniques.
- Malware: Gigabud Trojan (banking‑credential stealer) and Mantax Otax trojan.
- Data types at risk: Banking credentials, OTP tokens, personal identification numbers.
Source: Dark Reading