AUTO-UPDATED

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Gigabud banking trojan now utilizes a malicious Android app called Vwork to create hidden work profiles, allowing attackers to bypass security checks and compromise banking credentials.

Key Points

  • Security firm Group-IB identified that the Gigabud trojan installs Vwork to isolate tampered banking apps within a separate Android work profile.
  • This technique prevents banking security software from detecting the trojan, which remains hidden in the device's personal space.
  • The GoldFactory threat group, active since 2022, is linked to this campaign, which has targeted users in Indonesia, Brazil, Thailand, and several other nations.
  • Between February and July 2026, Group-IB observed approximately 1,469 compromised devices in Indonesia, resulting in estimated financial losses of $960,000.
  • Vwork is based on the open-source tool Shelter but has been modified to allow automated, unauthorized control by the malware operator.

Why it Matters

This development represents a sophisticated evolution in mobile malware, as attackers are now weaponizing legitimate Android security features to create "containers" that evade detection. By exploiting the separation between work and personal profiles, cybercriminals can maintain persistent control over banking apps while remaining invisible to standard security scans.
Internet Published by info@thehackernews.com (The Hacker News)
Read original