< Back to all clusters
[TECHNOLOGY] · Indonesia, Brazil, Colombia, Mexico, Egypt · 8 sources

started · updated

Gigabud banking trojan exploits Android work profiles to evade detection

Security researchers at Group-IB have identified a sophisticated evasion technique used by the Gigabud Android banking trojan. Attributed to the GoldFactory threat group, the malware utilizes a modified version of the Shelter app, known as Vwork, to exploit Android’s legitimate work profile feature.

By creating an isolated work profile, the malware clones legitimate banking applications into a separate workspace. This separation allows the trojan to bypass security measures because malware alerts or scans triggered in the user’s personal profile often fail to detect or correlate with malicious activity occurring within the isolated work profile. This enables fraudsters to conduct unauthorized transactions that appear to originate from a clean environment.

The infection typically begins when users sideload malicious apps—disguised as government portals, airlines, or tax offices—from phishing sites or social media. Once installed, the malware requests Accessibility permissions to gain remote control, uses overlays to steal credentials and lock screen PINs, and deploys the Vwork tool to establish the hidden profile.

While the full infection chain has been confirmed in Indonesia, the campaign targets at least 11 countries, including Brazil, Colombia, Mexico, Egypt, Laos, Morocco, the Philippines, Thailand, and Turkey. Group-IB reports significant financial losses in Indonesia, estimating approximately $960,939 stolen between February and July 2026.

Entities

Gigabud · GoldFactory · Group-IB · Mantax Otax · zLabs