Cybercriminals are using advanced Android malware that mimics banking applications within hidden Work Profiles to bypass traditional fraud detection systems. This method is linked to Gigabud, a Remote Access Trojan active since at least 2022, and Vwork, an application cloning tool based on open-source software. Attackers distribute phishing links via social media and messaging, tricking victims into installing malicious files disguised as legitimate utilities.
Once installed, the malware seeks Accessibility permissions and other capabilities to capture screen credentials and control the device. Vwork creates an isolated Work Profile to duplicate banking apps, allowing attackers to conduct fraudulent transactions without triggering security alerts in the personal space. Instances of counterfeit financial applications operating from these isolated environments have been documented, particularly in Indonesia.
Between February and July 2026, monitoring revealed around 1,469 compromised devices and 1,281 compromised account credentials in Indonesia, resulting in estimated financial losses of 8.2 crore rupees. The operation is believed to be part of a larger international campaign linked to GoldFactory, with malware targeting users in multiple countries including Brazil, Colombia, Egypt, and others.
Security experts warn that unusual Work Profile installations, duplicated banking apps, and unexpected requests for Accessibility permissions indicate a compromised device. Users are advised against sideloading APK files from private messages and should limit sensitive permissions to verified applications. Researchers emphasize the need for financial institutions to adopt behavioral analysis to detect unauthorized transactions effectively.