GoldFactory Clones Android Banking Apps to Evade Fraud Controls in Indonesia
Malware

Illustrative image generated with AI

GoldFactory Clones Android Banking Apps to Evade Fraud Controls in Indonesia

GoldFactory uses Gigabud and Vwork to clone Indonesian banking apps inside Android Work Profiles, evading fraud controls and causing $1M losses.

Text generated by artificial intelligence, published without human review. AI transparency

A mobile fraud campaign targeting Indonesia is abusing Android Work Profiles to run cloned banking applications in an isolated environment, weakening security controls tied to the phone’s primary profile.

The operation is attributed to GoldFactory, a Chinese-speaking cybercrime group specializing in financially motivated mobile attacks. Research published on Sept. 9 recorded about 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia between February and July. Estimated losses approached $1 million.

The technique combines the Gigabud Android banking Trojan with Vwork, an application derived from the open-source Shelter app-cloning project. Together, they give attackers remote access to a victim’s phone and a separate environment from which to execute fraudulent banking transactions.

Nearly $1 Million in Estimated Indonesian Losses

The recorded figures show that the campaign has moved beyond experimentation. Hundreds of potentially exposed banking sessions were associated with confirmed infections, producing direct financial consequences for Indonesian users.

Indonesia offers mobile fraud operators a substantial target population because Android phones, banking applications, digital payments and messaging platforms are widely used. Social-engineering content can also be localized around services that victims already recognize.

GoldFactory has previously tailored its impersonation campaigns to particular countries and institutions. Its themes have included national airlines, tax authorities and government websites, helping malicious applications appear relevant to their intended victims.

In one Indonesian case, investigators identified a fraudulent copy of a legitimate local bank’s application as the app used in the cloning workflow. The bank’s name, affected application versions and relevant Android versions have not been disclosed.

There is no identified software vulnerability or patch associated with the campaign. Instead, attackers combine malicious permissions, remote control and a legitimate Android isolation feature. That makes behavioral detection and control over application installation particularly significant.

Gigabud Establishes Control Before Vwork Creates the Clone

Gigabud, an Android banking Trojan active since 2022, provides the initial foothold. Its operators attempt to persuade the victim to install the malware and approve powerful Android permissions, especially accessibility access.

Once those permissions are available, Gigabud can inventory the phone and support live remote operation. Accessibility privileges may allow malware to observe interface content, interact with applications and automate actions that would otherwise require the user.

Vwork is then installed, often within minutes of the initial Gigabud infection. It does not maintain an independent command-and-control channel. Gigabud acts as the communications bridge, receiving instructions from the operator and passing them to Vwork.

The resulting attack sequence has six principal stages:

  1. Gigabud is installed on the Android device.
  2. The victim grants accessibility access and other requested permissions.
  3. Gigabud surveys the device and installs Vwork.
  4. Vwork creates an Android Work Profile.
  5. A banking application is reproduced inside that profile.
  6. The attacker remotely operates the cloned app and initiates transactions.

During remote activity, the malware can display a black screen to the victim. The user may therefore see no obvious indication that the phone is being controlled or that the banking application is active.

Work Profile Isolation Creates a Fraud-Detection Blind Spot

Android Work Profiles are designed to separate enterprise-managed applications and data from a user’s personal environment. In a legitimate deployment, an employer or device-management system uses that boundary to protect corporate resources.

GoldFactory turns the same separation into an evasion mechanism.

A security product may detect Gigabud or suspicious behavior in the personal profile and assign risk to the application instance operating there. When Vwork creates another profile, however, the cloned banking app gains a distinct context.

Controls that correlate risk only with the original app instance, personal profile or previously observed environment may fail to carry the warning into the Work Profile. To a bank, activity from the clone could consequently resemble access from a new or unrelated device context.

That disconnect matters because the fraudulent transaction still originates from the victim’s physical phone. The attacker can use the victim’s installed banking environment, credentials or active session while exploiting profile separation to weaken the relationship between the malware alert and the eventual cash-out attempt.

This is not a universal bypass of Android or banking security. Its effectiveness depends on how a bank, security application or fraud platform associates telemetry across profiles and app instances. Technical details about individual banks’ exposure have not been made public.

Gigabud-Compatible Samples Extend Beyond Indonesia

Indonesia is a prominent early target, but the supporting malware has a considerably wider footprint. Investigators identified Gigabud samples compatible with the Vwork technique in Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand and Turkey.

A compatible sample was also found in one unnamed member of the Gulf Cooperation Council. More broadly, Gigabud activity has appeared across Southeast Asia, South Asia, the Middle East, Africa and Latin America.

The presence of compatible malware does not establish the number of successful Vwork attacks in each country. Nor does it confirm that every Gigabud infection used Work Profile cloning. It does, however, indicate that the technique could be deployed outside Indonesia without creating an entirely new malware platform.

A separate Android threat is also affecting the Indonesian market. Zimperium’s zLabs team published findings on Sept. 9 about Mantax Otax, an aggressive banking Trojan with spyware capabilities linked to Indonesian actors and victims.

No operational relationship between Mantax Otax and GoldFactory has been established. The concurrent activity instead shows that Indonesian users face multiple Android financial-malware operations with different operators and toolsets, according to reporting on the app-cloning campaign.

An Unexpected Work Profile Is the Clearest Warning

For a consumer whose phone has never been configured by an employer, the unexplained appearance of a Work Profile is a strong reason to investigate. The profile is especially suspicious if it appears shortly after an unfamiliar application is installed.

Other warning signs include:

  • The same banking application appearing in both personal and Work Profile areas.
  • Accessibility privileges assigned to an app that has no credible need for them.
  • Applications installed from unofficial, deceptive or otherwise untrusted sources.
  • An unfamiliar app such as Vwork appearing soon after another installation.
  • A black screen or unusual loss of control while the phone remains active.
  • Banking access associated with a newly created profile or abnormal device context.

The absence of these visible signs does not prove a device is clean. Some activity may occur while the victim is distracted, and a duplicate application may not be obvious without reviewing the phone’s profile and application settings.

Anyone who finds an unexplained Work Profile or duplicate banking app should stop using the affected device for financial transactions and contact the bank through a trusted channel. Credentials and sessions may already be exposed. The device should also be examined for unauthorized accessibility permissions and recently installed applications.

Banks Must Correlate Risk Across Android Profiles

Banks and mobile-security providers cannot assume that one physical phone corresponds to one application environment. Detection systems should connect risk signals across personal and Work Profiles, duplicate app installations and newly created device contexts.

A sequence in which an unknown app receives accessibility access, another app appears minutes later, and a Work Profile is created should receive close scrutiny. The same applies when a banking app suddenly operates from a profile that has no history on the device.

Defenders should also look for mismatches between the user’s normal environment and the context of a transaction. A newly observed app instance should not automatically be treated as unrelated when the physical device or surrounding telemetry indicates an existing infection.

GoldFactory’s method succeeds by separating events that security systems may evaluate independently: malware installation in one profile and banking activity in another. Reconnecting those events is central to detecting the fraud before money leaves the account.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsGoldFactoryGigabudAndroid banking trojanVworkIndonesia banking fraudWork Profile abuse
Back to home