GoldFactory Gigabud banking trojan distribution campaign across 11 countries
Campaign
Summary
Hide ▲
Show ▼
The GoldFactory-linked Gigabud campaign is now using phishing sites, messengers and social media to push Android banking-trojan lures, extending activity across 11 countries and increasing fraud exposure. The operation impersonates airline, tax authority and government apps to reach victims. In Indonesia, the campaign’s infection chain was confirmed on real devices, showing the distribution model can lead directly to mobile banking fraud.
Related Happenings
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
Campaign
H score41
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
CampaignAbout this happening: A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
GoldFactory Coretax impersonation fraud campaign
Campaign
H score70
First: 19.02.2026 17:30
Last: 19.02.2026 17:30
Sources 1
About this happening:
The GoldFactory-linked fraud campaign now threatens Indonesian taxpayers at scale, with estimated losses of $1.5m to $2m. It ran from July 2025 and intensified in...
GoldFactory Coretax impersonation fraud campaign
CampaignAbout this happening: The GoldFactory-linked fraud campaign now threatens Indonesian taxpayers at scale, with estimated losses of $1.5m to $2m. It ran from July 2025 and intensified in...
Peru loan phishing campaign impersonating financial institutions across Latin America
Campaign
H score37
First: 21.01.2026 17:00
Last: 21.01.2026 17:00
Sources 1
About this happening:
A Peru-focused loan phishing campaign has expanded across Latin America, putting users' card numbers, PIN codes, and banking credentials at risk. The operation...
Peru loan phishing campaign impersonating financial institutions across Latin America
CampaignAbout this happening: A Peru-focused loan phishing campaign has expanded across Latin America, putting users' card numbers, PIN codes, and banking credentials at risk. The operation...
Timeline
-
09.09.2026 17:30 2 articles · 2h ago
Gigabud clones banking apps into Android work profiles
Initial DisclosureGroup-IB said Gigabud was being paired with Vwork, a weaponized fork of Shelter, to clone banking apps into an Android Work Profile and separate malware alerts from the ensuing transaction. The researchers said the full infection chain was confirmed on devices in Indonesia, and that Gigabud samples built to work with Vwork were targeting 11 countries including Brazil, Colombia, Egypt, Mexico, Thailand and Turkiye. In Indonesia between February and July 2026, Group-IB observed about 1469 compromised devices, 1281 potentially compromised logins, and estimated losses of roughly $960,939.
Show sources
- Gigabud Uses Android App Cloning to Evade Fraud Detection — www.infosecurity-magazine.com — 09.09.2026 17:30
- Gigabud Uses Android App Cloning to Evade Fraud Detection — www.infosecurity-magazine.com — 09.09.2026 17:30