Indonesia has become a testing ground for a novel Android banking malware method that leverages Google's Work Profile feature to bypass banking security measures. According to cybersecurity firm Group-IB, between February and July, approximately 1,469 devices were compromised, and nearly 1,281 login credentials were potentially exposed, leading to estimated losses of almost $1 million. The campaign is led by the GoldFactory group, a Chinese-speaking threat actor targeting mobile banking systems. Their goal is to create a cloned version of a victim's banking app within an isolated environment, making malware detection and fraud alerts less effective.

The primary malware used is Gigabud, a banking Trojan that has been active since 2022 and targets Android devices across Southeast Asia, South Asia, the Middle East, Africa, and Latin America. The malware can control a victim's phone remotely once installed and given the necessary permissions. A significant finding from Group-IB's research is the use of Vwork, a modified version of the open-source app-cloning application Shelter. Vwork gets installed shortly after Gigabud, allowing the creation of a separate work profile on a user's device, which isolates the cloned banking app from the user's personal profile.

This campaign has notably impacted Indonesia, with GoldFactory targeting numerous Indonesian banks, including both state-owned and private institutions. In one confirmed instance, a cloned version of a legitimate Indonesian bank's app was used to carry out fraudulent transactions.

Zimperium's zLabs research team also reports the Mantax Otax malware targeting Indonesia, stressing that the country is attractive to cybercriminals due to its large mobile banking user base. However, the threat of mobile banking malware is not exclusive to Indonesia, as it poses a global risk wherever mobile financial services are prevalent.

The Gigabud Trojan gains access to a device's accessibility permissions, allowing it to install Vwork and create a sandboxed work profile. This setup enables fraudsters to conduct transactions on the victim's phone while hiding their actions. Vwork relies on Gigabud for command execution, evading detection by malware and fraud detection systems that typically focus on the user's personal profile.

Key indicators of a potential infection include the creation of an isolated work profile on a personal device without user initiation and unexpected app installations from non-legitimate sources. Users should also be cautious of duplicate banking apps across profiles and apps requesting unnecessary accessibility permissions.