TechNewsReel
Live

GoldFactory Group Steals Nearly $1M via Android App-Cloning Campaign

Attackers weaponized a fork of the open-source app Shelter to hide fraudulent transactions within isolated Android Work Profiles.

TechNewsReel Newsroom · September 11, 2026

The Chinese-speaking threat group GoldFactory has deployed a sophisticated mobile campaign in Indonesia that weaponizes Android's enterprise features to steal nearly $1 million from banking users. By cloning legitimate financial apps into isolated environments, the attackers successfully bypassed fraud detection systems to execute unauthorized transactions.

Between February and July, the campaign compromised approximately 1,469 devices and 1,281 logins in Indonesia. According to research from Group-IB, these attacks resulted in estimated losses of $960,939. The operation relies on the Gigabud Trojan to deploy Vwork, a weaponized fork of the open-source application known as Shelter. Vwork is specifically modified to remove cross-profile restrictions and hide its launcher icon from the user's view.

The Work Profile Evasion

This tactic exploits the Android Work Profile feature, which is designed to separate professional and personal data on a single device. Vwork creates a hidden Work Profile to clone banking apps into an isolated environment. This is a critical evasion strategy because security signals detected in a user's personal profile often do not carry over to the isolated work profile. Consequently, fraudulent transactions appear to originate from a clean device, effectively decoupling the malware's presence from the transaction environment.

Group-IB researchers noted that the operator carries out transactions directly on the victim's phone while a black screen hides the activity from the user. This allows the attackers to cash out even if the device's primary profile has already triggered security alerts.

Industry Implications

This campaign represents a significant shift in mobile fraud by turning legitimate enterprise tools into weapons. By leveraging the architectural isolation of Work Profiles, GoldFactory has found a way to neutralize the fraud protection controls that banks rely on to identify compromised devices. The use of a modified open-source tool like Shelter further demonstrates how attackers can rapidly adapt existing software to create stealthy, specialized malware.

What to Watch

Gigabud has been active since 2022, targeting regions across Southeast Asia, the Middle East, and Latin America. Attackers typically use social engineering lures—impersonating government portals, airlines, or tax authorities—to trick users into sideloading malicious APKs. Security teams should monitor for unauthorized Work Profile creations and the presence of modified app-cloning tools, as this method of isolation provides a blueprint for future banking Trojans to evade detection.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.