Researchers say the Gigabud Android banking trojan now clones a victim’s real banking app into a hidden Android Work Profile, so fraud can happen in a separate space that may not trigger the same malware and fraud signals. Victims are tricked into installing what looks like legitimate apps (airline, tax, or government), after which the malware can capture credentials and hide on-device activity while transactions occur.
Key findings
- Gigabud is being paired with “Vwork,” a weaponized cloning tool that uses Android Work Profiles to isolate a cloned banking app from detections in the personal profile.
- Operators “install the malware, wait, then clone the bank's app into the new profile and transact from there,” making the bank see activity as coming from an “unrecognized device with no malware history.”
- Gigabud spreads via “phishing sites, messengers and social media,” posing as “airline, tax authority or government apps.”
- The malware uses fake login screens to steal banking credentials and overlays/black screens to conceal what is happening during fraud.
- Group-IB observed impact in Indonesia (Feb–Jul 2026): “about 1469 compromised devices and 1281 potentially compromised logins,” with estimated losses around “$960,939.”
- Banks are advised to treat “Two or more” behavioral signals (e.g., unexpected Work Profile, empty isolated environment, suspicious accessibility use) as “a high-risk session.”
Who’s being targeted
- Commonly targeted roles: All staff who use mobile banking (especially on Android), Finance teams handling payments, Customer support and fraud operations teams at banks.
- Affected industries: Banking, Financial services.
- Attack channels: website.
- Impersonated: Government agency / airline / tax authority app publisher (as a fake Android app).
Awareness takeaways
- Only install mobile apps from official app stores; treat links to APK downloads as suspicious.
- Be wary of apps that ask for Accessibility or overlay permissions, especially at first launch, because that can enable account takeover and hidden activity.
- For banks: flag sessions where a Work Profile appears unexpectedly and combine multiple device signals to identify high-risk activity.
Red flags to watch for
- App is not installed from an official app store
- App requests high-risk permissions on first launch (accessibility/overlay) that don’t match its purpose
- Pressure to install an ‘update’ from a link or unofficial site
Read the video transcript
You get a message: “Required update – download the official tax authority app to complete verification.” Looks legit, logo and all. But it’s Gigabud with a tool called Vwork. Once you install it, on first launch it begs for Accessibility and overlay permissions, then silently clones your real banking app into a hidden Android Work Profile. Here’s the nasty part: they use fake login screens to grab your banking password, then a black screen overlay while they move money from that cloned app. To the bank, it looks like a clean, new device with no malware history. Your move: if any ‘government, airline, or tax’ app wants you to sideload an APK and turn on Accessibility or overlay on first launch, stop, delete it, and use the official app store instead.