The Gigabud Android banking trojan has evolved, now capable of cloning banking applications into a distinct Android work profile. This innovative approach provides fraudsters with a method to sever the connection between malware alerts and subsequent transactions, creating a more insidious threat to mobile banking security.
In research released on September 9, Group-IB detailed how Gigabud is being utilized alongside Vwork, a modified version of the open-source Android cloning app Shelter. The cybersecurity firm attributed both developments to a group known as GoldFactory, suggesting that they have either developed or customized these tools for their illicit activities.
The full scope of this infection chain has been confirmed solely on devices located in Indonesia. However, Gigabud samples designed to operate with Vwork have been identified as targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye.
Vwork Hides Banking Apps in Work Profiles
Vwork leverages Android’s Work Profile feature to facilitate app cloning within an isolated environment. Unlike Shelter, which is intended for use by the device owner, Vwork allows its cloning capabilities to be accessed by any application on the device. Group-IB noted that Gigabud samples incorporate specific code, including three new commands to provision the work profile, clone a designated app, and report back on the cloning process. This cloning operation necessitates a token from an external authorization server, which Gigabud is adept at retrieving.
The crux of this operation lies in detection isolation. Applications residing in one profile remain largely hidden from signature-based detection systems in another. Consequently, an alert triggered in the personal profile does not activate in the newly created work profile. Operators can install the malware, bide their time, and then clone the banking app into the new profile to execute transactions. To the bank, these payments appear to originate from an unrecognized device devoid of any malware history.
During the fraudulent activity, fake login screens capture banking credentials, while an invisible overlay collects lock screen codes. A black screen masks the ongoing actions on the device, further complicating detection efforts.
Fraud Detection Faces a New Separation Problem
Between February and July 2026, Group-IB reported observing approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated financial losses nearing 0,939. These figures, while significant, are described as indicative rather than fully representative of the broader regional landscape.
Active since 2022, Gigabud reaches its victims through phishing sites, messaging platforms, and social media, often masquerading as applications from airlines, tax authorities, or government entities. Upon initial launch, it requests accessibility access, overlay permissions, and battery exemptions—permissions that enable the operator to gain control over the device.
Group-IB identified six behavioral signals that banks should monitor, including:
- A work profile appearing on a phone that the user never configured.
- Matching banking app markers across different profiles.
- An otherwise empty isolated environment.
- Accessibility access granted to an app that has no legitimate need for it.
When two or more of these indicators are present, they should be treated as a high-risk session. Additionally, Group-IB recommends implementing device binding to prevent unauthorized logins from authorizing payments and urges users to download applications exclusively from official stores.