GoldFactory Malware Clones Banking Apps via Android Work Profiles to Steal Funds
A high-severity Android malware campaign, linked to the threat group GoldFactory, has been targeting Indonesian users by tricking them into sideloading a malicious APK disguised as an airline, tax, or government application. Once installed, the malware Gigabud harvests banking credentials and screen lock codes, then deploys a secondary tool called Vwork to create an Android Work Profile on the victim's device. Vwork clones the victim's legitimate banking app inside this isolated Work Profile, allowing attackers to register it as a new device with the bank without triggering existing risk signals. Operating behind a black screen overlay, attackers remotely control the cloned app to carry out unauthorized fund transfers that victims are unlikely to notice in real time. Group-IB, which published its findings on September 11, 2026, confirmed actual financial losses and recommends restricting sideloading, limiting accessibility permissions via MDM policies, and strengthening bank-side authentication for newly registered devices.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in