Marthio Marthio
TechnologyBusiness

Android banking trojan Gigabud exploits app cloning to bypass fraud checks

Cybercriminals linked to the financially motivated group GoldFactory are using a modified fork of the open-source app Shelter to isolate fraudulent banking activity from malware alerts.

Research published by Group-IB on September 9 revealed that cybercriminals behind the Gigabud Android banking trojan use a weaponized app-cloning tool to hide fraud. The attackers pair Gigabud with Vwork, a modified fork of the open-source application Shelter. This combination creates a separate Work Profile containing banking applications. Security checks run within this cloned environment do not see malware operating in the personal profile on the same device. Researchers confirmed the complete infection chain on devices in Indonesia. They identified Gigabud samples targeting 11 countries: Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and one unnamed Gulf nation.

Banking appAndroid securityCybercriminalsFraud monitoringGroup IbGoldfactoryIndonesiaFinancial threat groupMalware alerts