Android Work Profile Abused to Deliver Banking Trojans in Indonesia
The GoldFactory threat group exploited Android's legitimate Work Profile feature as an attack vector to deploy the Gigabud banking trojan, demonstrating how attackers weaponize trusted OS features to bypass user suspicion. A parallel campaign distributing Mantax Otax malware signals a coordinated, multi-pronged effort to harvest financial credentials from Indonesian Android users. Both campaigns succeed largely because users are unaware that app-cloning and sideloading can silently introduce malicious software that mimics legitimate banking applications. The financial impact is significant, as these trojans are purpose-built to exfiltrate sensitive banking credentials and payment data. Organizations and individuals must treat mobile devices with the same security rigor applied to traditional endpoints.
Tactical Insight
Immediate actions
- Disable or restrict Android Work Profile creation on unmanaged personal devices used for corporate or banking access.
- Warn users never to install banking apps from sources outside official app stores (Google Play) and to verify publisher authenticity before installing.
- Enable Google Play Protect and ensure it is actively scanning all installed applications.
Long-term improvements
- Deploy a Mobile Device Management (MDM) or Mobile Threat Defense (MTD) solution to enforce app allowlisting and detect trojanized applications.
- Implement conditional access policies that block banking or corporate resource access from devices that fail device health attestation checks.
- Conduct regular security awareness training specifically covering mobile phishing, app-cloning techniques, and social engineering lures.
Detection measures
- Monitor for anomalous data exfiltration patterns from mobile endpoints, particularly to unfamiliar or foreign IP addresses.
- Integrate mobile threat intelligence feeds into your SIEM to receive indicators of compromise (IOCs) for known banking trojans like Gigabud and Mantax Otax.
- Establish baseline behavioral profiles for mobile apps and alert on deviations such as unexpected permission requests or background data transmission.