ZeroHour
Dark Readingpublished ()ingested Alexander Culafi
Part of a story covered by 6 sources: “GoldFactory's Gigabud Android Banking Trojan Uses Weaponized Shelter Fork Vwork to Clone Banking Apps Into Hidden Work Profiles and Evade Fraud Detection” — merged summary and timeline →

Indonesia Hit by Android Banking App-Cloning Campaign

mediumThreat actor exploited in the wildimportance 45
AI summary · glm-5.3-flash

GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.

The GoldFactory threat group is running an app-cloning campaign against Android banking customers in Indonesia, abusing the Android Work Profile feature to deliver its Gigabud trojan. The Mantax and Otax malware families are spreading through separate distribution channels. Abusing Work Profile to install or conceal cloned banking apps is a notable mobile technique, though the article reports no victim counts or loss figures.

  • GoldFactory abuses the Android Work Profile feature to deliver the Gigabud banking trojan in Indonesia.
  • Cloned banking apps are the campaign's delivery vehicle, targeting Indonesian Android banking customers.
  • Mantax and Otax malware are spreading through separate distribution channels.
Full article

The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.