[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7VpD1E9fnQItKxT-HFlHdK1f9P02ZFdhE6zuCmP6Uo4":3},{"article":4,"iocs":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":28},"014d7fc8-222d-4bc8-8781-245098233cf5","Indonesia Hit by Android Banking App-Cloning Campaign","indonesia-hit-by-android-banking-app-cloning-campaign-133227","The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.","The GoldFactory threat group has been observed exploiting the Android Work Profile feature to deliver the Gigabud Trojan, a banking trojan. Concurrently, a separate campaign is spreading the Mantax Otax malware, indicating a broader threat landscape targeting Android users in Indonesia. Both malware strains are designed to steal financial information.","GoldFactory uses Android Work Profile to deliver Gigabud Trojan; Mantax Otax spreads separately.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fmobile-security\u002Findonesia-android-banking-app-cloning-campaign","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltaf1f330952367016\u002F6aa3075b6e51441d4542eee8\u002Findonesia_flag-peng_song-GettyImages-1371211038.jpg?width=720&quality=80&disable=upscale","2026-09-11T01:00:00+00:00","2026-09-11T02:00:25.049252+00:00",7,[18,21],{"name":19,"type":20},"GoldFactory","threat_actor",{"name":22,"type":23},"Android Work Profile","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":11,"name":26,"slug":27},"Malware","malware",[29,34,36],{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":35},{"id":24,"icon":11,"name":26,"slug":27},{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[42,45],{"type":27,"value":43,"context":44},"Gigabud Trojan","Banking trojan delivered via Android Work Profile exploitation.",{"type":27,"value":46,"context":47},"Mantax Otax","Banking trojan spreading separately in Indonesia."]