← Back to Feed

Indonesia Hit by Android Banking App-Cloning Campaign

September 11, 2026 · Dark Reading · Severity: HIGH

Indonesia is being hit by an Android banking app-cloning campaign where attackers create fake versions of popular banking apps. The malware steals credentials, intercepts SMS two-factor codes, and can initiate fraudulent transactions, targeting users of major Indonesian banks. This campaign underscores the need for enhanced mobile security and user awareness.

Key Takeaways

  • Indonesia is facing an Android banking app-cloning campaign where attackers create fake versions of popular banking apps to steal credentials and intercept SMS two-factor codes. The malware can initiate fraudulent transactions, posing a significant threat to users of major Indonesian banks. This campaign highlights the need for enhanced mobile security measures.
  • The fake banking apps are distributed through third-party app stores and phishing links, tricking users into installing them. Once installed, the malware captures login credentials and two-factor authentication codes, enabling account takeover. Users should only download apps from official stores and verify app authenticity.
  • This campaign targets Indonesian banks specifically, indicating a focused threat actor with regional interests. The use of SMS interception to bypass two-factor authentication is a sophisticated technique. Banks should educate customers about these threats and consider implementing more secure authentication methods.
☕ Buy a Coffee