Gigabud Abuses Android Work Profiles to Hide Bank Fraud

Gigabud Vwork Android work profile cloning a fake banking app to evade fraud detection

An Android feature devised to separate personal and corporate applications has become a hiding place for banking fraud. Group-IB has described the pairing of Gigabud and Vwork, which, in a confirmed chain, creates a work profile, places a counterfeit banking program inside it, and severs the chain of signals to the bank, all on a single device.

How Vwork Turns a Legitimate Tool Against the User

Vwork is based on the open-source application Shelter, which uses the Android work profile as an isolated space. Ordinary Shelter requires action from the smartphone’s owner, yet in Vwork the developers stripped away the restrictions on external calls. Gigabud can command it to create a profile, clone the desired application, retrieve the list of copies, and launch them. Group-IB details the full technique in its analysis of Vwork app cloning tied to Gigabud and GoldFactory.

Why Profile Separation Defeats Bank Checks

Separating profiles helps circumvent part of the checks performed by banking applications. The signature mechanism inside the work profile does not necessarily see Gigabud, which remains in the device’s personal area. A bank may first notice malicious activity without any financial operation, and later receive a transfer already originating from the new profile, perceiving it as an event from a different device.

The Attack Sequence Step by Step

Before creating the hidden environment, Gigabud gains control through Android’s Accessibility service, gathers the list of installed programs, and identifies the banks of interest. A fake window intercepts banking credentials, while a separate invisible layer steals the unlock code. During the transfer, the trojan controls the screen on the victim’s behalf, and a black overlay conceals the operator’s actions.

Confirmed Losses in Indonesia

Group-IB confirmed the full sequence, Gigabud, then Vwork, then the fake banking application, on infected devices in Indonesia. From February to July 2026, the company observed roughly 1,469 compromised devices there, some 1,281 potentially compromised logins, and estimated losses of about $960,939. These figures reflect only the portion of activity visible to Group-IB.

A Wider Target List and Active Development

Gigabud samples compatible with Vwork were found for 11 countries and regions, including Brazil, Mexico, Thailand, and Turkey, though the report notes no confirmed Vwork infections beyond Indonesia. Group-IB analyzed a single Vwork sample and considers the program to be under active development. Some of its new functions prove unstable on Android builds close to AOSP.

Attribution and Defensive Advice

Group-IB links both programs to GoldFactory, which has already wielded Gigabud in fraudulent campaigns against Android users. For protection, the company advises installing applications only from official stores, never granting ordinary programs access to Accessibility, and using a second factor for banking operations that does not depend on SMS.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply