The Gigabud banking trojan now utilizes a malicious Android app called Vwork to create hidden work profiles, allowing attackers to bypass security checks and compromise banking credentials.
Key Points
- Security firm Group-IB identified that the Gigabud trojan installs Vwork to isolate tampered banking apps within a separate Android work profile.
- This technique prevents banking security software from detecting the trojan, which remains hidden in the device's personal space.
- The GoldFactory threat group, active since 2022, is linked to this campaign, which has targeted users in Indonesia, Brazil, Thailand, and several other nations.
- Between February and July 2026, Group-IB observed approximately 1,469 compromised devices in Indonesia, resulting in estimated financial losses of $960,000.
- Vwork is based on the open-source tool Shelter but has been modified to allow automated, unauthorized control by the malware operator.