Indonesia has become a pioneering location for a new Android banking malware method that leverages Google's Work Profile feature to circumvent banking security measures. Researchers at Group-IB have reported that they detected around 1,469 compromised devices and 1,281 potential login attempts in Indonesia from February to July, resulting in an estimated loss of nearly $1 million. The lure and infection context differ by region (attackers impersonated national airlines, tax authorities, and government portals), but the malware generally gives attackers extensive control over a target device.

Related: Fake Bahrain Alert App Deployed with Android Surveillance Malware This latest research highlights an important finding: while Group-IB was investigating Gigabud infections, they discovered the presence of Vwork, a fork of the open-source Android app cloning application Shelter.

Related: ToxPanda Banking Trojan Becomes a Targeted Enterprise Threat Nico Chiaraviglio, the chief scientist at Zimperium, explains that Indonesia is an appealing destination for this type of malware due to its large, mobile population and widespread use of mobile banking, digital payment, messaging platforms, and Android devices. This technique also utilizes a cloned environment to bypass fraud protection controls. Group-IB also advises users to watch for identical banking application installations across profiles, accessibility settings enabled for apps that shouldn't require them, or any unexpected app installations from non-legitimate sources shortly after a previous phone installation.