Executive Summary
Between February and July 2026, the Chinese-speaking threat group GoldFactory deployed a sophisticated Android banking malware campaign targeting Indonesia, resulting in 1,469 compromised devices and nearly $1 million in losses. The attackers used the Gigabud banking Trojan in combination with Vwork, a modified app-cloning tool, to exploit Android's Work Profile feature. This technique allowed fraudsters to clone legitimate banking applications into isolated environments where security controls and fraud detection systems could not follow, enabling them to conduct transactions while evading detection mechanisms that were triggered in the victim's primary profile.
This incident highlights the evolution of mobile banking threats as attackers increasingly target regions with high mobile payment adoption and develop novel evasion techniques that exploit legitimate enterprise security features for malicious purposes.
Why This Matters Now
Mobile banking malware is rapidly evolving to exploit legitimate enterprise features like Android Work Profiles, creating new attack vectors that traditional security controls cannot detect. With Indonesia's massive mobile banking adoption and similar techniques spreading globally, organizations must urgently reassess their mobile security strategies.
Attack Path Analysis
GoldFactory threat group executed a sophisticated Android banking malware campaign targeting Indonesian users through social engineering lures impersonating legitimate services, deploying the Gigabud banking Trojan to gain device control, then using the Vwork app to clone banking applications into isolated Android Work Profiles to evade fraud detection systems. The attack enabled real-time transaction manipulation while hiding activities behind black screens, ultimately resulting in financial theft from compromised banking applications across multiple Indonesian financial institutions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims were infected through social engineering campaigns where GoldFactory impersonated national airlines, tax authorities, and government portals to distribute the Gigabud banking Trojan via malicious Android applications
MITRE ATT&CK® Techniques
Spearphishing Link
Disable or Modify Tools
Process Hollowing
Setuid and Setgid
Remote Desktop Protocol
Keylogging
Browser Session Hijacking
Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Deploy Intrusion Detection System
Control ID: 11.5.1
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
DORA – Identification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Device Compliance and Health
Control ID: Device Security
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Web Filtering
Control ID: A.8.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target of GoldFactory's Gigabud banking trojan using Android Work Profile cloning to evade fraud detection systems and facilitate unauthorized transactions.
Financial Services
High risk from mobile banking malware exploiting accessibility permissions and profile isolation to bypass security controls, threatening transaction integrity and customer data.
Telecommunications
Critical infrastructure enabling mobile banking attacks through compromised Android devices, requiring enhanced mobile security controls and encrypted traffic monitoring capabilities.
Government Administration
Targeted by threat actors impersonating tax authorities and government portals to distribute malware, compromising citizen data and public service delivery systems.
Sources
- Indonesia Hit by Android Banking App-Cloning Campaignhttps://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaignVerified
- Group-IB Research: GoldFactory Android Banking Malware Campaignhttps://www.group-ib.com/blog/goldfactory-gigabud-android-banking-malware/Verified
- Zimperium zLabs: Mantax Otax Banking Trojan Analysishttps://www.zimperium.com/blog/mantax-otax-banking-trojan-indonesia/Verified
- Android Work Profile Security Documentationhttps://developer.android.com/work/securityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained GoldFactory's mobile banking campaign by limiting malware communication paths and reducing the scope of fraudulent operations across compromised Android devices.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Malicious application downloads and initial command channels would likely face restricted network paths, potentially limiting the malware's ability to establish reliable communication with threat actor infrastructure during the infection phase.
Control: Zero Trust Segmentation
Mitigation: Device-to-network privilege escalation attempts would likely encounter segmented access controls, constraining the malware's ability to expand its reach beyond the initial compromised mobile endpoint to backend banking infrastructure.
Control: East-West Traffic Security
Mitigation: Application cloning operations and cross-profile communications would likely face constrained network pathways, reducing the malware's ability to coordinate between original and cloned banking applications across isolated Android Work Profiles.
Control: Multicloud Visibility & Control
Mitigation: Remote control sessions and proxy command channels would likely encounter visibility-driven blocking mechanisms, constraining the threat actors' ability to maintain persistent live operation capabilities across the compromised mobile device fleet.
Control: Egress Security & Policy Enforcement
Mitigation: Fraudulent transaction data and captured credentials would likely face controlled egress pathways, constraining the volume and frequency of sensitive financial information leaving compromised mobile devices toward threat actor collection infrastructure.
Despite network constraints, fraudulent transactions would likely still occur on compromised devices, though the overall financial impact scope could be reduced through limited communication pathways and constrained data exfiltration capabilities affecting campaign coordination effectiveness.
Impact at a Glance
Affected Business Functions
- Mobile Banking Services
- Digital Payment Processing
- Customer Account Management
- Financial Transaction Security
Estimated downtime: N/A
Estimated loss: $1,000,000
Banking credentials, authentication tokens, and financial transaction data of approximately 1,469 compromised devices across Indonesian banking institutions. Personal banking information and account access credentials were exposed through the Gigabud trojan's remote access capabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation policies to prevent unauthorized app installations and profile creation activities that bypass mobile security controls
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound communications from mobile banking applications to prevent data exfiltration
- • Enable Multicloud Visibility & Control capabilities to monitor anomalous mobile device behaviors and detect suspicious automation patterns in banking application interactions
- • Establish Threat Detection & Anomaly Response systems to identify unusual Android Work Profile creation and app cloning activities on consumer devices
- • Implement Cloud Native Security Fabric controls to provide real-time inspection and policy enforcement for mobile application traffic and prevent banking Trojan command and control communications



