Hackers Clone Banking Apps into Hidden Profiles, Android Malware Raises New Fraud Concerns

Exploiting Android Work Profiles to Evade Security Checks

In a concerning development, cybercriminals have begun utilizing sophisticated Android malware that replicates targeted banking applications within concealed Work Profiles. This tactic enables attackers to execute unauthorized transactions while circumventing conventional fraud detection systems. Security researchers have traced this operation back to Gigabud, a Remote Access Trojan that has been active since at least 2022, in conjunction with Vwork, an application cloning utility derived from the open-source software Shelter.

The campaign employs deceptive phishing links disseminated through social media and messaging platforms, enticing victims to install malicious files disguised as government, tax, or airline utilities, as well as counterfeit financial services.

Once the malware secures device privileges, Gigabud seeks Accessibility permissions, overlay capabilities, and exemptions from battery optimizations to capture screen credentials and gain remote control over the smartphone. The attack unfolds as Vwork establishes an isolated Android Work Profile, within which it duplicates the targeted banking application. This separation is crucial; since the operating system treats personal and enterprise workspaces as distinct environments, security alerts triggered by malware in the personal space do not automatically extend to the isolated setup. This division creates a façade of safety for attackers during fraudulent transactions.

Investigators have confirmed instances where counterfeit financial applications operated from within these isolated work environments, with documented activity emerging from Indonesia. Notably, Vwork has been observed concealing its launcher icon while receiving remote commands from Gigabud to initiate setup, duplicate applications, and send inventory logs back to control servers.

Significant Financial Losses Recorded Across Global Targets

Monitoring efforts conducted between February and July 2026 revealed approximately 1,469 compromised devices and 1,281 compromised account credentials in Indonesia alone, leading to estimated financial losses of 8.2 crore rupees. Analysts caution that these figures represent only the visible telemetry, hinting at a much larger international campaign linked to GoldFactory. Malware samples compatible with this operation have been detected targeting users across various countries, including Brazil, Colombia, Egypt, Laos, Mexico, Morocco, the Philippines, Thailand, Turkiye, and a member nation of the Gulf Cooperation Council.

The findings illustrate a coordinated strategy wherein cybercrime syndicates exploit legitimate device management features that were originally designed to segregate professional and personal phone usage.

Behavioral Safeguards Urged as Threat Tactics Evolve

Security experts are sounding the alarm that unexplained Work Profile installations, duplicated banking applications, and irregular requests for Accessibility permissions are clear signs of a compromised smartphone. Users are strongly advised to refrain from sideloading APK files received via private messages and to restrict sensitive permissions to verified applications sourced from official digital storefronts.

A researcher at Algoritha Security emphasized that merely detecting standalone malicious files is no longer adequate to combat modern banking fraud. Financial institutions and payment networks must pivot towards behavioral analysis, correlating recent profile creation, overlay activity, and unusual transaction parameters to intercept unauthorized fund transfers before they are completed.

AppWizard
Hackers Clone Banking Apps into Hidden Profiles, Android Malware Raises New Fraud Concerns