The Gigabud Android banking trojan can clone banking applications into a separate Android work profile, allowing fraudsters to bypass malware alerts during transactions. Research by Group-IB, released on September 9, indicates that Gigabud is used with Vwork, a modified app for cloning, attributed to the GoldFactory group. The infection has been confirmed in Indonesia but targets 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye. Vwork uses Android's Work Profile feature to isolate cloned apps, making them less detectable. This allows operators to install malware, clone banking apps, and execute transactions without raising alarms. During fraud, fake login screens capture credentials, and an invisible overlay collects lock screen codes. From February to July 2026, 1,469 devices were compromised in Indonesia, with financial losses nearing 0,939. Gigabud spreads through phishing and social media, requesting permissions to control devices. Group-IB identified six behavioral signals for banks to monitor as indicators of high-risk sessions. Recommendations include device binding and downloading apps only from official stores.