Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The emergence of the Gigabud banking trojan has taken a more sophisticated turn, as it now installs a secondary Android application that establishes a work profile on compromised devices. This revelation comes from a report released by security firm Group-IB on September 9. The work profile, typically designated for employer-related applications, creates a distinct environment that keeps its contents separate from the personal space of the device. This separation allows the trojan to evade detection from the banking app’s internal malware checks, thereby facilitating fraudulent transactions that appear unrelated to any alerts raised on the device. Group-IB has confirmed the full operational chain on infected devices in Indonesia.

According to Android’s platform documentation, any application within the main profile can initiate the setup of a work profile, with users being informed about its functionality prior to its creation. Group-IB noted that banking applications are equipped with security codes designed to detect known malware present on the device. However, scans conducted from within a work profile do not extend to the personal space where the trojan resides.

Gigabud functions as a remote access trojan, granting its operator real-time control over the infected phone. Active since 2022, it is linked to a group identified as GoldFactory, which employs deceptive tactics to reach users by masquerading as legitimate applications, such as those of a national airline, tax office, or government portal, often installed from unofficial sources.

Upon its initial launch, Gigabud requests various permissions, including Accessibility access, the ability to overlay other apps, and permission to run in the background to conserve battery life. Granting Accessibility access is pivotal, as it allows the operator to gain substantial control over the device. Once granted, the trojan compiles a list of all applications on the phone, enabling the identification of potential banking targets. When the victim attempts to access their legitimate banking app, a counterfeit login screen overlays the genuine interface, capturing keystrokes. Additionally, an invisible overlay collects the phone’s lock screen code.

Group-IB identified the secondary application as Vwork, which shares architectural similarities and class names with Shelter, an open-source tool that utilizes the work profile feature to allow users to isolate or duplicate applications. The key distinction lies in control; while Shelter is operated manually by the device owner, Vwork extends similar functionalities to other applications, enabling it to set up a work profile, clone apps, and manage their contents autonomously.

Group-IB reported that Vwork has been stripped of checks that would typically prevent other applications from accessing its functions. Before cloning any app, Vwork communicates with an external server for authorization, with Gigabud executing commands specifically tailored for it. Unlike Shelter, which guides users through multiple screens to create a profile, Vwork simplifies this process to a single prompt, presented in Chinese, as noted by Group-IB.

In the confirmed cases from Indonesia, the installation sequence was as follows: Gigabud was deployed first, followed shortly by Vwork, and then the tampered banking application. Notably, the report highlighted that the banking app introduced into the work profile was not a duplicate of the victim’s original app but rather a counterfeit version of a legitimate Indonesian banking application.

Group-IB analyzed a specific sample of Vwork, indicating that it remains under active development, with some added functionalities exhibiting instability on Android versions close to the open-source release. The report did not specify which devices or Android versions were affected by this technique.

Samples of Gigabud designed to operate with Vwork have been detected targeting various countries, including Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and an unnamed Gulf Cooperation Council nation. These samples have yet to be confirmed as infections, with only the Indonesian chain validated.

Between February and July 2026, Group-IB recorded approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, estimating losses around 0,000. These figures reflect Group-IB’s observations rather than a comprehensive assessment of the country, and the report did not clarify how many devices contained Vwork.

Group-IB has established a connection between both tools and the GoldFactory group, citing a segment of Vwork’s code referencing Gigabud package names, shared network indicators, and developer logs written in Chinese, although it has refrained from disclosing these indicators publicly.

Checking a Phone for a Work Profile

Users can verify the presence of a work profile within their phone’s settings. Google’s guidance for Android users provides a clear outline for locating and removing such profiles:

  • Navigate to Settings, then Passwords and accounts. A Work tab will appear if a work profile is present.
  • Applications within a work profile will display a small briefcase badge on their icons.
  • To delete the work profile, access the Work tab, select Remove Work Profile, and then Delete. Google states that this action will erase all data stored within the profile.
  • Ensure that the application responsible for setting up the profile has been removed. Group-IB noted that Vwork conceals its icon from the app launcher, although it remains visible in a file manager.

Google’s instructions presume that the phone belongs to the user, as a profile owned by an employer cannot be removed by the individual. Group-IB’s report does not clarify whether deleting the profile mitigates risks while Gigabud remains installed in the personal space.

To safeguard against such threats, Group-IB advises users to download applications exclusively from official stores, to deny Accessibility access to any app that does not serve as an accessibility tool, and to implement a second factor for banking applications that does not rely on SMS.

For banks, Group-IB highlights several indicators to watch for, including the appearance of a work profile on a personal device that was not intentionally set up, the same banking application showing installation markers in both profiles, a profile lacking the usual applications, and Accessibility access enabled for an app that does not require it.

Vwork was initially discovered during previous research by Group-IB into GoldFactory’s campaign involving tampered banking applications in Southeast Asia, published in December 2025. The firm noted that Vwork has only been observed in the context of this campaign.

While the concept of embedding a banking application within a container to bypass its defenses is not novel, as evidenced by Promon’s FjordPhantom in 2023, which operated a legitimate banking app within a virtual container, Vwork employs a contrasting approach. It utilizes an existing barrier provided by Android to position the trojan beyond the reach of the checks outlined by Group-IB.

AppWizard
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks