The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
Key Insights
10 editorial insights.
Cybercriminals have launched a coordinated campaign that hijacks Android banking applications across Indonesia, leveraging the Work Profile feature to inject the Gigabud Trojan and a separate Mantax Otax payload. The operation targets millions of mobile banking users, turning legitimate finance apps into conduits for credential theft and unauthorized transactions. Immediate attention is required because the technique bypasses many existing mobile‑security controls, potentially exposing a large swath of the region’s rapidly digitising consumer base.
The GoldFactory group exploits Android’s managed Work Profile, a sandbox intended for corporate data, by embedding malicious code into the profile’s provisioning process. Once the profile is activated, the Gigabud Trojan gains system‑level permissions, allowing it to overlay fake login screens on popular banking apps and capture one‑time passwords. A parallel strain, Mantax Otax, follows a similar delivery chain but uses a distinct command‑and‑control infrastructure, making detection harder for signature‑based scanners. Both payloads are signed with stolen certificates to appear legitimate, and they employ dynamic code loading to evade static analysis.
Mobile banking in Southeast Asia has surged, with Indonesia alone reporting over 200 million smartphone users and a 45 % year‑over‑year increase in digital payment transactions. This growth has attracted not only fintech innovators but also threat actors seeking high‑value targets. The Android platform dominates the region, holding roughly 85 % market share, which amplifies the impact of any malware that can piggyback on native OS features. Competitors such as local banks and e‑wallet providers are now racing to harden their apps, while regional regulators are drafting tighter guidelines on app certification and certificate management.
India’s fintech ecosystem, already the world’s largest, feels the ripple effects of the same attack vector. Indian banks that ship Android apps with Work Profile support may inherit the same exposure, especially as they expand services to neighboring markets. Developers using third‑party SDKs for UI customization could inadvertently introduce the same code‑reuse vulnerabilities. The Reserve Bank of India’s recent push for real‑time fraud monitoring and mandatory security audits for mobile apps underscores the urgency for Indian firms to audit their provisioning workflows and enforce strict certificate hygiene.
Key Highlights
- Deploys malicious Work Profile to embed Gigabud Trojan across banking apps
- Uses stolen signing certificates and dynamic code loading to evade detection
- Targets a market where Android holds ~85% share, affecting millions of users
- Fintech developers and security teams gain critical insight into new evasion tactics
- Expect rapid patch cycles and updated security policies from banks within weeks
Real-World Impact
Banking app users in Indonesia and neighboring countries now face heightened risk of credential theft, prompting banks to roll out emergency updates. Security analysts, mobile developers, and compliance officers must prioritize forensic reviews of provisioning scripts and certificate inventories. Financial institutions may see a short‑term dip in transaction volumes as users adopt multi‑factor authentication and biometric safeguards.
Why This Matters
The campaign demonstrates how legitimate OS features can be weaponised at scale, signaling a shift toward more sophisticated, platform‑native malware. CTOs should reassess their mobile‑security architecture, incorporating runtime integrity checks and zero‑trust principles for app provisioning. Developers need to avoid hard‑coding certificates and adopt automated signing pipelines that detect anomalies.
As Android continues to dominate the mobile landscape in Asia, the next wave of banking malware will likely refine the Work Profile abuse technique. Stakeholders should monitor upcoming Android security patches and collaborate with regional CERTs to share indicators of compromise before the threat matures.
Deep Analysis
Multi-Source Intelligence
Found this useful? Share it!
