Android Banking Trojan Targets 11 Countries Using Cloned Work Profiles
Cybercriminals are deploying a banking trojan called Gigabud that exploits Android Work Profiles to evade fraud detection across ten identified nations.
A newly discovered banking trojan named Gigabud is infecting smartphones in Indonesia and targeting users in eleven specific countries, including Brazil, Colombia, Egypt, Mexico, the Philippines, and Türkiye. According to research published by cybersecurity firm Group-IB on September 9, the threat group behind this malware operates under the alias GoldFactory. The attackers use a tool known as Vwork, which is a modified version of the open-source Android application Shelter. They pair Gigabud with Vwork to create a separate Work Profile, placing banking applications inside this isolated environment. This setup allows malware running in the personal profile to remain invisible to security checks operating within the cloned banking app. By separating work data from personal data, the criminals can initiate payments through the isolated profile while appearing distinct from earlier malicious activity on the same physical device. Researchers confirmed the complete infection chain on devices in Indonesia and identified code samples designed to interact with Vwork.