Gigabud Hides Fake Bank App in Android Work Profile

The Hacker News · High sophistication
Last updated September 10, 2026

Researchers say the Gigabud banking trojan is being installed via fake apps (e.g., pretending to be an airline, tax office, or government portal) and then uses an Android “work profile” to hide a tampered banking app. Victims are tricked into granting powerful permissions, after which attackers can overlay fake login screens to steal credentials and run fraudulent transactions while masking what’s happening on the screen. Group-IB confirmed the full infection chain on devices in Indonesia and estimates nearly $1M in observed losses.

Key findings

  • Gigabud installs a second app (“Vwork”) that creates an Android work profile and places a tampered banking app inside it to evade some banking app malware checks.
  • Gigabud spreads via “a fake app posing as a national airline, a tax office, or a government portal, installed from outside the official store.”
  • On first launch, the malware asks for high-risk permissions, especially Accessibility, which enables attacker control of the device.
  • When a victim opens their real banking app, the trojan can display a fake login overlay to steal keystrokes and capture the device lock code via an invisible overlay.
  • Attackers can perform transactions through Accessibility while “a black screen covers what is happening.”
  • Group-IB confirmed the full chain on infected devices in Indonesia and observed 1,469 compromised devices with estimated losses of about $960,000 (Feb–Jul 2026).

Who’s being targeted

  • Commonly targeted roles: All employees (mobile users), Finance/Payments teams, Executives (high-value banking targets), Helpdesk/IT support (mobile security hygiene).
  • Affected industries: Banking/Financial Services, Consumers/Mobile banking users.
  • Attack channels: website.
  • Impersonated: A national airline, tax office, or government portal (impersonation via fake app), The fake app’s ‘setup’ / ‘security requirements’ screens (app-level pretext), A legitimate bank app (tampered/fake version placed in a work profile).

Awareness takeaways

  • Only install mobile apps from official app stores; treat ‘download this app from a link’ as a high-risk request.
  • Never grant Accessibility access (or ‘draw over other apps’) to apps that don’t clearly need it, this can give attackers control of the device.
  • Watch for unexpected Android work profiles or briefcase-badged apps on a personal phone; they can indicate a hidden container used for fraud.
  • Use a banking second factor that does not rely on SMS to reduce account takeover risk.

Red flags to watch for

  • App is installed from outside the official app store
  • App requests powerful permissions that don’t match its purpose (especially Accessibility)
  • Branding/pretext implies urgency or required access to proceed
  • Accessibility requested by a non-accessibility app
  • Requests to ‘draw over other apps’ without a clear need
  • Permission prompts framed as required to proceed
  • Unexpected ‘work profile’ appears on a personal phone
  • Banking app appears duplicated across personal and work profiles
  • Briefcase badge on icons you didn’t set up
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a link: “Install our official airline app update to continue your booking.” Looks legit… but it’s not from Google Play. Behind that fake airline, the Gigabud trojan quietly installs a second app called “Vwork,” creates an Android work profile, and hides a tampered banking app inside it. On first launch it demands Accessibility and ‘draw over other apps.’ Give it that, and when you open your real banking app, Gigabud drops a fake login screen on top, steals your password and lock code, then runs transactions behind a blacked-out screen. Your move: if an app from a link, not the app store, asks for Accessibility or to draw over other apps, stop right there and uninstall it. Don’t tap Allow.

Similar attacks

Fake Airline Apps Push Android Banking Fraud

Fake Airline Apps Push Android Banking Fraud

Researchers report two Android banking malware families (ToxicPanda 2.0 and GoldDigger) that rely on tricking people into installing malicious apps and granting powerful permissions. GoldDigger campaigns impersonate airlines and shopping retailers and then abuse Android Accessibility to take over…

August 20, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Hundreds of Fake Chrome VPNs Hijack Browsing

Hundreds of Fake Chrome VPNs Hijack Browsing

Researchers found 737 Chrome VPN/proxy extensions that impersonated well-known privacy brands and routed users’ browser traffic through attacker-controlled SOCKS5 proxies. The activity mainly targeted Russian-speaking users trying to access blocked services, putting the operator in a position to…

August 12, 2026
Fake China Police App Tied to Android RAT Ring

Fake China Police App Tied to Android RAT Ring

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked Android remote-access tool (RAT) framework called “Flying Eagle.” The tooling lets criminals build convincing look‑alike apps and then steal…

July 31, 2026