Indonesia Hit by Android Banking App-Cloning Campaign

The flag of Indonesia.
Source: peng song via Getty Images

Indonesia has emerged as an early testing ground for a new Android banking malware technique that uses Google's Work Profile feature to help fraudsters evade banking security controls.

According to Group-IB, its researchers observed roughly 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia between February and July, resulting in nearly $1 million in estimated losses.

In research published Sept. 9, Group-IB described an Android banking malware technique used by the threat actor GoldFactory. GoldFactory is a Chinese-speaking threat group focused on mobile banking cyberattacks for financial gain. The ultimate goal is to clone a victim's banking app into an isolated environment where malware detections and fraud signals may not follow.

The malware used in this campaign is Gigabud, a banking Trojan targeting Android devices and active since 2022. It's used in attacks across Southeast Asia, South Asia, the Middle East, Africa, and Latin America. While the lure and infection context varies by region (attackers impersonated national airlines, tax authorities, and government portals), the malware generally grants an attacker immense influence over a target device. Once installed and granted the necessary permissions, the malware gives operators live remote control of the victim's phone.

What's significant about this latest research is that while researching Gigabud infections, Group-IB discovered the presence of an application called Vwork, a fork of the open source Android app-cloning application Shelter. Group-IB observed instances where Vwork would be installed within minutes of the initial Gigabud infection.

The research revealed that GoldFactory is deploying a new defense evasion technique through Android's Work Profile function, a feature intended for enterprise use that creates a separate, isolated space on the user's phone where apps are installed independently from one's personal profile.

Indonesia Targeted by Banking Trojans

Group-IB identified Vwork-compatible Gigabud samples targeting countries including Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, Philippines, Thailand, Turkey, and "a GCC [Gulf Cooperation Council] member state." But researchers Pavel Naumov and Bryan Karunachandra emphasized the impact on Indonesia in particular.

In one confirmed case, "the copy was a fake version of a real Indonesian bank's app," the researchers explained.

Karunachandra, who is Group-IB's APAC fraud analyst for Group-IB, tells Dark Reading GoldFactory, "has targeted around a dozen Indonesian banks, including both state-owned and private institutions" as part of this campaign.

This research was published at a similar time frame to a Sept. 9 blog post from Zimperium's zLabs research team detailing "Mantax Otax," an aggressive banking Trojan malware targeting Android devices linked to Indonesian threat actors and targeting Indonesian victims.

Nico Chiaraviglio, chief scientist at Zimperium, tells Dark Reading that Indonesia is an attractive target for this kind of malware because it combines a large, highly mobile population with widespread mobile banking, digital payment, messaging platform, and Android device use.

While this makes for a broad pool of potential targets, Chiaraviglio stresses that Indonesia is not alone. "Mobile banking malware is a global threat, and attackers tend to concentrate activity wherever mobile financial services are widely used and their social-engineering campaigns can be effectively localized," he says.

A Novel Evasion Tactic Targeting Android Phones

According to Group-IB, once the victim gets infected through the Gigabud Trojan, Gigabud obtains accessibility permissions, inventories the devices, installs Vwork, and uses this second app to create a work profile and clone a banking application already on the user's phone into that sandboxed profile. With everything in place, "the operator carries out transactions directly on the victim's phone while a black screen hides what is happening. A cloned environment is used to evade fraud protection controls."

Vwork does not include command-and-control (C2) functionality of its own and instead relies on receiving commands through Gigabud as a proxy. Group-IB points out that many fraud and malware detection systems build their risk signals around a specific app instance or profile; even if security tools detect malware on one's personal profile, that may not carry over into the newly created work one.

"From the bank's perspective, the transaction originates from a new device and may appear unrelated to the previously detected malware activity," according to Group-IB's research blog post. "Meanwhile, the malware detection alert has already been triggered in the victim's personal profile but will not fire in the newly created work profile due to a lack of infection signals. By exploiting this separation between profiles, fraudsters can effectively break the link between the malware detection signal and the fraudulent transaction, allowing them to evade existing security controls and successfully cash out."

The earliest reliable warning sign in the chain occurs when an ordinary consumer phone never set up by an employer's IT department creates an isolated work profile without user input. Group-IB also recommends users look out for identical banking application installations across profiles, accessibility access enabled for apps that should not require it, or any unexpected app installation from a non-legitimate source being installed shortly following a previous phone install.

source: DarkReading