Zero Day Room
Live
Defence

Gigabud Trojan Clones Banking Apps to Bypass Fraud Detection

The Gigabud Android banking trojan now uses a weaponized app cloner called Vwork to isolate fraudulent transactions in a separate work profile, breaking

The Gigabud Android banking trojan now uses a weaponized app cloner called Vwork to isolate fraudulent transactions in a...

The Gigabud Android banking trojan has been updated to clone banking applications into an isolated Android work profile. This technique severs the connection between a malware detection alert and the fraudulent transaction that follows, security firm Group-IB reported on September 9.

Group-IB attributes the development of both Gigabud and the weaponized cloning tool Vwork to a threat group it calls GoldFactory. The full infection chain has so far been confirmed only on devices in Indonesia, though malware samples built for this method target users in 11 countries.

Vwork Weaponizes App Cloning for Isolation

Vwork is a malicious fork of the legitimate open-source Android app Shelter, which uses the operating system's Work Profile feature. While Shelter is designed for user-controlled app cloning, Group-IB said Vwork exposes its cloning functions as an interface that any other application on the device can call.

Gigabud samples now contain dedicated code for Vwork, including three new commands. These commands provision the work profile, clone a specified application, and report back on what has been cloned. The cloning process itself requires a token from an external authorization server, which Gigabud retrieves.

The core objective is detection isolation. Applications running in one Android profile are largely invisible to signature-based security scans in another. Consequently, an alert triggered in the device's personal profile will not fire in a work profile created after the alert was raised.

Attack Flow Conceals Fraudulent Transactions

Operators install the malware and wait. They then clone the target banking app into the newly created work profile and conduct transactions from there. From the bank's perspective, the payment appears to originate from an unrecognized device with no prior history of malware infection.

Fake login screens capture the victim's banking credentials. A separate, invisible overlay steals the device's lock screen code. During the actual fraudulent transaction, a black screen is displayed to conceal the activity on the smartphone.

Campaign Scale and Infection Methods

Group-IB observed the campaign in Indonesia between February and July 2026. The firm identified approximately 1469 compromised devices and 1281 potentially compromised login sets, with estimated losses of roughly $960,939. Group-IB described these figures as indicative rather than representative of the entire region.

Gigabud, active since 2022, typically reaches victims through phishing sites, messaging apps, and social media. It often poses as applications for airlines, tax authorities, or government services. Upon first launch, it requests accessibility access, overlay permission, and a battery usage exemption. Granting accessibility access is the point where the operator gains control of the device.

The malware samples configured to work with Vwork target users across multiple countries.

Behavioral Signals for Banks to Detect Abuse

Group-IB outlined six behavioral signals that financial institutions can monitor to detect this scheme. Two or more signals occurring together should be treated as a high-risk session, the firm advised.

The signals include a work profile appearing on a phone the user never personally set up, matching banking application markers across both personal and work profiles, and an otherwise empty isolated environment. Other red flags are accessibility service access granted to an application with no legitimate need for it, the presence of known malicious packages, and the installation of applications from unknown sources.

Group-IB's additional advice included implementing strong device binding to prevent stolen login credentials from authorizing payments. For users, the firm reiterated the critical importance of downloading applications only from official stores. The research highlights a growing challenge for fraud detection systems that rely on linking malicious activity directly to the transaction endpoint.

Related coverage

More from Defence