Indonesia Hit by Android Banking App-Cloning Campaign

MediumDark Reading · Alexander Culafi·

The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

At a glance

Severity
Mediumfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
Android
Threat actors & malware
None named
Coverage
1 outlet· first seen 2026-09-11 01:00 UTC
Priority
41/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. Dark ReadingEstablished SourceFirst reported

    2026-09-11 01:00 UTC

Related stories