The GoldFactory threat group exploits the Android Work Profile feature to deploy the Gigabud trojan in Indonesia, while Mantax Otax operates independently, targeting mobile banking applications.
The nation of Indonesia has been the target of a cyberattack campaign focused on cloning mobile banking applications. This malicious operation is attributed to the GoldFactory threat group, which has deployed the Gigabud trojan as a central component of its strategy.
GoldFactory's attack method involves exploiting the Android Work Profile feature. This feature, designed by Google to separate work and personal data on Android devices, creates an isolated environment for corporate applications and data. Its purpose is to enhance security and data management in enterprise environments. However, GoldFactory has managed to manipulate this functionality for its malicious objectives. By exploiting Work Profile, the group can stealthily install and operate the Gigabud trojan, potentially evading standard security detections and achieving persistence on the compromised device. The ability to clone banking applications within a work profile suggests an attempt to trick users into interacting with fraudulent versions of their legitimate financial applications, facilitating credential theft or transaction interception.
The Gigabud trojan is the central malicious software in this campaign. Its typical functionality in mobile banking attacks includes the ability to overlay fake interfaces over legitimate applications, intercept SMS to bypass two-factor authentication, and steal sensitive information from the device. The distribution of this trojan by exploiting Android Work Profile indicates an advanced technique to circumvent operating system defenses and application security measures. Parallel to GoldFactory's activities, the report mentions that Mantax Otax spreads separately. This suggests the existence of multiple campaigns or threat actors operating in the same region or using similar attack vectors against the mobile banking sector, which amplifies the overall risk for users and financial institutions in Indonesia.
The exploitation of a security feature like Android Work Profile underscores the sophistication of current threat groups. For users, the cloning of banking applications represents a direct risk of financial fraud and identity theft. For banking institutions, these campaigns imply an erosion of customer trust in mobile banking security, as well as significant operational costs associated with fraud detection, attack mitigation, and the implementation of additional security measures. The coexistence of multiple threats like Gigabud and Mantax Otax in the same region indicates an active and complex mobile threat landscape. Continuous vigilance and the implementation of multi-layered security solutions are imperative to counter the evolution of these tactics.
The crypto ecosystem is volatile. If you decide to invest, do it safely using our affiliate links in the most trusted exchanges. You get a welcome bonus and we get a small commission.
Disclaimer: This content is not financial advice. Do your own research before investing.
