GoldFactory and Mantax Otax Target Indonesian Android Bank Users

Two concurrent Android banking malware campaigns — GoldFactory's Gigabud trojan and Mantax Otax ransomware-spyware hybrid — target Indonesian users with credential theft and harassment.
Table of Contents
    Add a header to begin generating the table of contents

    Two separate but concurrent Android banking malware campaigns are targeting Indonesian users through distinct technical approaches: GoldFactory’s Gigabud trojan exploits Android Work Profile isolation to hide malicious banking apps from security checks, while Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal data, and harass victims. Group-IB published analysis of the Gigabud campaign on September 9, with multiple security outlets reporting the Mantax Otax threat between September 10 and 11.

    Gigabud Trojan Weaponizes Android Work Profiles to Evade Detection

    The GoldFactory threat group’s Gigabud trojan creates a separate Android work profile on infected devices and drops a tampered banking app inside it. Android work profiles are typically reserved for employer-managed applications, creating an isolated container that standard security checks do not scan. The malicious banking app operates within this protected space, keeping credential-stealing activity hidden from antivirus and fraud detection tools that monitor the main user profile.

    This technique represents a significant evolution in Android banking malware evasion strategies. Work profiles were designed to separate personal and corporate data on employee-owned devices, with enterprise mobility management systems controlling apps within the work profile while leaving the user’s personal space untouched. Security solutions respect this boundary, scanning the personal profile where users install apps from unknown sources but avoiding the work profile under the assumption that it contains only IT-vetted corporate applications.

    How Work Profile Isolation Defeats Banking Security Controls

    Work profiles function as separate environments on a single Android device, with their own app installations, data storage, and access permissions. Security software scanning the primary user profile cannot inspect apps or data inside the work profile without explicit permission. Gigabud abuses this separation to run a credential-harvesting banking app that mimics legitimate bank interfaces while capturing login credentials, transaction authorization codes, and account details.

    Mantax Otax Combines File Encryption, Data Theft, and Victim Harassment

    Mantax Otax takes a different approach, combining ransomware and spyware functions in a single malware package. The malware encrypts files on infected devices, exfiltrates data to attacker-controlled servers, and harasses victims through automated spam calls and messages. This harassment layer distinguishes Mantax Otax from traditional banking trojans or ransomware families, adding psychological pressure to the technical attack.

    The hybrid ransomware-spyware design maximizes attacker leverage over victims. File encryption creates immediate operational impact, forcing victims to choose between losing access to photos, documents, and app data or paying a ransom. Data exfiltration enables extortion threats even if victims restore from backups or accept data loss — attackers can threaten to publish stolen personal information or contact lists. The automated harassment through spam calls and messages adds a third pressure vector, creating sustained psychological stress that may push victims toward compliance.

    Indonesian Banking Sector Faces Dual Mobile Threats

    Indonesian banking customers face credential theft and account takeover through the Gigabud campaign, while Mantax Otax victims contend with data loss, file encryption, and sustained harassment. The campaigns demonstrate the evolution of Android malware techniques to evade security controls designed for traditional threat patterns. The simultaneous emergence of two distinct, sophisticated Android malware families targeting the same geographic market indicates that Indonesian users present a high-value target for cybercriminals, likely due to growing smartphone banking adoption and gaps in mobile security awareness.

    Group-IB researchers warned Android users to avoid sideloading apps and verify app sources before installation. The Gigabud and Mantax Otax campaigns both rely on users installing malicious apps from outside the Google Play Store, where Google’s malware scanning and review processes provide a baseline defense layer. Sideloading — installing apps from third-party stores, direct downloads, or messaging app links — bypasses this protection and remains a primary distribution vector for Android banking malware.

    Banks in Indonesia were advised to implement additional authentication controls that can detect anomalous login patterns even when credentials are valid. These controls might include device fingerprinting to identify when known credentials are used from unfamiliar devices, geolocation checks to flag logins from unexpected locations, and behavioral analysis to detect transactions inconsistent with the account holder’s normal patterns.

    The work profile abuse technique used by Gigabud has broader implications for enterprise mobile security beyond Indonesia. Organizations with bring-your-own-device programs that use Android work profiles to separate corporate and personal data must now consider that the work profile boundary, designed as a security feature, can be weaponized by malware to hide from security tools. Mobile device management systems may need to expand scanning capabilities into work profiles, though this raises privacy concerns when work profiles contain legitimately installed corporate applications.

    Related Posts