Threat Brief — 2026-09-11 — Android banking trojan campaign targets Indonesia
Executive summary
The GoldFactory threat group has launched an Android banking app-cloning campaign in Indonesia, using the Android Work Profile feature to deliver the Gigabud trojan. This development connects two previously separate Android malware threads — Gigabud's work-profile evasion and the Mantax Otax ransomware/spyware combination — under a single geographic targeting lens. No other fresh findings were ingested in the last four hours.
Top items
- GoldFactory targets Indonesia with Gigabud via Android Work Profiles — Dark Reading reports that the GoldFactory threat group is exploiting Android's Work Profile feature to deliver tampered banking app clones carrying the Gigabud trojan to Indonesian users. The same article notes that Mantax Otax — previously reported as a separate Android threat combining ransomware, spyware, and victim harassment — is spreading in parallel. This extends the Gigabud work-profile evasion story first reported 2026-09-10 by The Hacker News, now with confirmed geographic targeting of Indonesia and explicit linkage to the Mantax Otax campaign. (src: Dark Reading)
Themes
Mobile banking trojan convergence in Southeast Asia: The linkage of GoldFactory/Gigabud and Mantax Otax under a single Indonesia-focused campaign suggests either coordinated or opportunistic convergence of two distinct Android malware families in the same region. Both leverage legitimate Android platform features — Work Profiles in Gigabud's case — to evade detection, a pattern worth monitoring as banking-app cloning techniques mature.
