Gigabud Abuses Android Work Profiles to Hide Bank Fraud
An Android feature devised to separate personal and corporate applications has become a hiding place for banking fraud. Group-IB has described the pairing of Gigabud and Vwork, which, in a confirmed chain, creates a work profile, places a counterfeit banking program inside it, and severs the chain of signals to the bank, all on a single device.
How Vwork Turns a Legitimate Tool Against the User
Vwork is based on the open-source application Shelter, which uses the Android work profile as an isolated space. Ordinary Shelter requires action from the smartphone’s owner, yet in Vwork the developers stripped away the restrictions on external calls. Gigabud can command it to create a profile, clone the desired application, retrieve the list of copies, and launch them. Group-IB details the full technique in its analysis of Vwork app cloning tied to Gigabud and GoldFactory.
Why Profile Separation Defeats Bank Checks
Separating profiles helps circumvent part of the checks performed by banking applications. The signature mechanism inside the work profile does not necessarily see Gigabud, which remains in the device’s personal area. A bank may first notice malicious activity without any financial operation, and later receive a transfer already originating from the new profile, perceiving it as an event from a different device.
The Attack Sequence Step by Step
Before creating the hidden environment, Gigabud gains control through Android’s Accessibility service, gathers the list of installed programs, and identifies the banks of interest. A fake window intercepts banking credentials, while a separate invisible layer steals the unlock code. During the transfer, the trojan controls the screen on the victim’s behalf, and a black overlay conceals the operator’s actions.
Confirmed Losses in Indonesia
Group-IB confirmed the full sequence, Gigabud, then Vwork, then the fake banking application, on infected devices in Indonesia. From February to July 2026, the company observed roughly 1,469 compromised devices there, some 1,281 potentially compromised logins, and estimated losses of about $960,939. These figures reflect only the portion of activity visible to Group-IB.
A Wider Target List and Active Development
Gigabud samples compatible with Vwork were found for 11 countries and regions, including Brazil, Mexico, Thailand, and Turkey, though the report notes no confirmed Vwork infections beyond Indonesia. Group-IB analyzed a single Vwork sample and considers the program to be under active development. Some of its new functions prove unstable on Android builds close to AOSP.
Attribution and Defensive Advice
Group-IB links both programs to GoldFactory, which has already wielded Gigabud in fraudulent campaigns against Android users. For protection, the company advises installing applications only from official stores, never granting ordinary programs access to Accessibility, and using a second factor for banking operations that does not depend on SMS.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.