Application Security

Sophisticated Android App-Cloning Campaign Targets Indonesian Banking Users

FORTSECURE GLOBAL· 2026-09-11🛰 Dark Reading
#Banking#Malware#Mobile Security#Application Security
Sophisticated Android App-Cloning Campaign Targets Indonesian Banking Users

Cybercriminals are abusing Android's Work Profile feature to distribute aggressive banking trojans, posing severe financial and data security risks.

Attackers Weaponize Android Work Profiles

A sophisticated mobile cyber campaign targeting mobile banking users in Indonesia has surfaced, leveraging deceptive techniques to bypass traditional security layers. Threat groups, notably the GoldFactory syndicate, have been observed abusing Android's native 'Work Profile' enterprise feature. This mechanism allows malicious actors to deploy aggressive financial malware, including the Gigabud banking trojan, alongside independent campaigns distributing the Mantax Otax malware family.

By manipulating users into setting up compromised enterprise configurations, attackers isolate their malicious payload within a managed environment. This setup facilitates unauthorized screen recording, keystroke capture, and the interception of two-factor authentication (2FA) SMS codes without raising typical system alerts. The cloned applications convincingly mimic legitimate financial institutions, deceiving users into handing over credentials and session tokens.

Recommendations for Defense and Risk Mitigation

To safeguard mobile endpoints and organizational assets against advanced app-cloning tactics, FORTSECURE GLOBAL advises implementing the following controls:

  • Enforce Mobile Device Management (MDM): Restrict personal and unmanaged devices from configuring arbitrary Work Profiles when accessing corporate resources. Implement strict Mobile Application Management (MAM) policies.
  • User Awareness Programs: Educate end-users never to install configuration profiles, enterprise provisioning certificates, or third-party APKs distributed via SMS, messaging platforms, or social media.
  • Continuous Threat Monitoring: Financial institutions should integrate real-time mobile fraud detection capable of spotting cloned application signatures and unauthorized remote access tool (RAT) behaviors.

แหล่งที่มา: Dark Reading เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 01:00:00 GMT บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: Dark Reading

เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 01:00:00 GMT

บทความต้นฉบับ: https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog