The Gigabud banking trojan installs a secondary Android application called Vwork, which creates a work profile on compromised devices to evade detection from banking app security measures. This work profile separates its contents from the personal space of the device, allowing fraudulent transactions without triggering alerts. Group-IB confirmed this operational chain in Indonesia, where Gigabud has been active since 2022 and is linked to the GoldFactory group, which uses deceptive tactics to distribute the trojan. Vwork simplifies the creation of a work profile and communicates with an external server for authorization before cloning apps. The report indicates that Vwork has been detected in various countries, while approximately 1,469 devices and 1,281 logins were compromised in Indonesia, leading to estimated losses of around ,000,000. Users can check for a work profile in their phone's settings and are advised to download apps only from official stores and to deny unnecessary Accessibility access.