news.mlab.sh
Back to the feed
threat-intel

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

High
Summary

A new Android banking Trojan, Gigabud, is utilizing a secondary app called Vwork to bypass banking app security measures. Vwork creates a work profile, isolating the tampered banking app within it, effectively shielding it from the banking app's own malware checks. Group-IB researchers discovered this technique in Indonesia, where they observed a chain of installations – Gigabud, Vwork, and a fake Indonesian bank app – resulting in significant financial losses. The technique is linked to GoldFactory and has been used in Southeast Asia since December 2025.

A new Android banking Trojan, Gigabud, is leveraging a secondary app called Vwork to circumvent banking app security protocols. Vwork creates a work profile, a feature typically reserved for employer apps, to isolate a tampered banking app from the phone’s main security checks. This effectively shields the fraudulent banking app from the checks performed by the legitimate banking app itself, allowing it to steal credentials and conduct unauthorized transactions. Group-IB researchers first identified this technique in Indonesia, where they documented a chain of installations: Gigabud first, followed by Vwork within minutes, and then a fake version of a real Indonesian bank’s app.

Between February and July 2026, Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses of around $960,000. These numbers represent Group-IB’s observations and should not be considered a complete picture of activity within the country. The report does not specify how many of these devices had Vwork installed.

Group-IB linked both Gigabud and Vwork to GoldFactory, a threat actor group. Indicators of compromise, including code references and developer logs, were withheld to prevent further exploitation. The technique is not new; Promon described FjordPhantom in 2023, which utilized a similar method to run a real banking app within a virtual container to alter its behavior and bypass Android’s security walls. Vwork, conversely, utilizes a pre-existing Android feature – the work profile – to achieve its goal.

Google provides guidance on how to check for and remove work profiles. Users can find the work profile in their settings under ‘Passwords and accounts’ – a ‘Work’ tab will appear if a profile exists. Apps within a work profile display a small briefcase badge on their icons. To delete the profile, users can select ‘Remove Work Profile’ within the ‘Work’ tab, which removes everything stored inside the profile. However, Group-IB notes that Vwork keeps its icon out of the app launcher, though it still appears in a file manager.

Group-IB advises users to install apps only from official stores, to refuse Accessibility access to any app that is not an accessibility tool, and to use a second factor for banking apps that does not rely on SMS. Banks should be vigilant for signs such as a work profile appearing on a consumer phone without being set up, the same banking app showing install markers in both profiles, a profile holding none of the apps a person would normally have, and Accessibility switched on for an app with no reason to need it.

Read the full article at The Hacker News