Gigabud Clones Banking Apps to Dodge Fraud Alerts

Infosecurity Magazine · High sophistication
Last updated September 9, 2026

Researchers say the Gigabud Android banking trojan now clones a victim’s real banking app into a hidden Android Work Profile, so fraud can happen in a separate space that may not trigger the same malware and fraud signals. Victims are tricked into installing what looks like legitimate apps (airline, tax, or government), after which the malware can capture credentials and hide on-device activity while transactions occur.

Key findings

  • Gigabud is being paired with “Vwork,” a weaponized cloning tool that uses Android Work Profiles to isolate a cloned banking app from detections in the personal profile.
  • Operators “install the malware, wait, then clone the bank's app into the new profile and transact from there,” making the bank see activity as coming from an “unrecognized device with no malware history.”
  • Gigabud spreads via “phishing sites, messengers and social media,” posing as “airline, tax authority or government apps.”
  • The malware uses fake login screens to steal banking credentials and overlays/black screens to conceal what is happening during fraud.
  • Group-IB observed impact in Indonesia (Feb–Jul 2026): “about 1469 compromised devices and 1281 potentially compromised logins,” with estimated losses around “$960,939.”
  • Banks are advised to treat “Two or more” behavioral signals (e.g., unexpected Work Profile, empty isolated environment, suspicious accessibility use) as “a high-risk session.”

Who’s being targeted

  • Commonly targeted roles: All staff who use mobile banking (especially on Android), Finance teams handling payments, Customer support and fraud operations teams at banks.
  • Affected industries: Banking, Financial services.
  • Attack channels: website.
  • Impersonated: Government agency / airline / tax authority app publisher (as a fake Android app).

Awareness takeaways

  • Only install mobile apps from official app stores; treat links to APK downloads as suspicious.
  • Be wary of apps that ask for Accessibility or overlay permissions, especially at first launch, because that can enable account takeover and hidden activity.
  • For banks: flag sessions where a Work Profile appears unexpectedly and combine multiple device signals to identify high-risk activity.

Red flags to watch for

  • App is not installed from an official app store
  • App requests high-risk permissions on first launch (accessibility/overlay) that don’t match its purpose
  • Pressure to install an ‘update’ from a link or unofficial site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a message: “Required update – download the official tax authority app to complete verification.” Looks legit, logo and all. But it’s Gigabud with a tool called Vwork. Once you install it, on first launch it begs for Accessibility and overlay permissions, then silently clones your real banking app into a hidden Android Work Profile. Here’s the nasty part: they use fake login screens to grab your banking password, then a black screen overlay while they move money from that cloned app. To the bank, it looks like a clean, new device with no malware history. Your move: if any ‘government, airline, or tax’ app wants you to sideload an APK and turn on Accessibility or overlay on first launch, stop, delete it, and use the official app store instead.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake LinkedIn Tests and Job Interviews Push Malware

Fake LinkedIn Tests and Job Interviews Push Malware

This weekly threat bulletin includes real-world campaigns where attackers impersonate recruiters and use fake hiring steps to trick people into running malicious files. One campaign uses fake LinkedIn coding tests delivered via cloud links, and another uses fake job interviews with trojanized macOS…

September 7, 2026
Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI…

September 2, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026