GoldFactory's Gigabud Android Banking Trojan Uses Weaponized Shelter Fork Vwork to Clone Banking Apps Into Hidden Work Profiles and Evade Fraud Detection
Group-IB's 'Hook for Gold' investigation links GoldFactory's Gigabud Android banking trojan (active since 2022) to Vwork, a weaponized fork of the open-source Shelter app cloner that hides its icon and clones victims' banking apps into isolated Android Work…
Group-IB's 'Hook for Gold' investigation ties the GoldFactory group's Gigabud Android malware, active since 2022, to Vwork, a weaponized (Malwarebytes: trojanized) version of the open-source Android app cloner Shelter. Most sources describe Gigabud as an Android banking trojan; Cyber Security News characterizes it as an Android RAT. Vwork hides its launcher icon and abuses Android Work Profile provisioning to create an isolated work profile into which it clones the victim's banking app; The Hacker News describes the profile as hosting a tampered/fake banking app that is invisible to the malware scans banking apps run in the personal profile. Infosecurity Magazine adds that Gigabud now ships dedicated code for working with Vwork, exposing its cloning functions so any installed app can call them, and GBHackers lists the C2 commands initVwa, cloneApp and uploadCloneApps that manage the virtualized environment. Because fraudulent transactions run from the cloned app in the work profile, banks see a fresh, unrecognized, apparently malware-free device, weakening the correlation between malware signals detected in the personal profile and the fraud. Gigabud obtains device control via Accessibility and overlay permissions (Malwarebytes adds battery-optimization exemptions), reading screens, capturing credentials and lock-screen/device PIN codes via fake login screens and overlays, automating taps and/or remotely controlling devices; The Hacker News notes a black screen conceals the operator's actions during fraudulent payments. Distribution uses fake airline, tax, government and (per Cyber Security News) banking apps pushed via phishing sites, messaging apps and social media; Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures. Scope: Cyber Security News and The Hacker News count 11 targeted countries - Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye and a GCC state - while GBHackers frames it regionally as Southeast Asia, Latin America, the Middle East, Africa and beyond, naming Brazil, Indonesia, Egypt, Mexico, the Philippines and Thailand among others; only the Indonesian infection chain is confirmed end-to-end (Infosecurity Magazine, The Hacker News). In Indonesia between February and July 2026, Group-IB observed about 1,469 compromised devices, 1,281 potentially compromised logins (Cyber Security News, Infosecurity Magazine) and estimated losses of roughly $960,939 (GBHackers,…
- Attribution: Group-IB's 'Hook for Gold' investigation links Gigabud, active since 2022, to the GoldFactory group; sources describe Gigabud as an Android banking trojan (GBHackers, Infosecurity Magazine, The Hacker News, Malwarebytes) or an…
- Vwork is a weaponized/trojanized fork of the open-source Shelter app cloner that hides its launcher icon and abuses Android Work Profile provisioning to clone victims' banking apps into an isolated work profile.
- Mechanics: Infosecurity Magazine reports Gigabud ships dedicated code exposing Vwork's cloning functions to any installed app; GBHackers lists C2 commands initVwa, cloneApp and uploadCloneApps managing the virtualized environment; The…
- Fraud effect: transactions from the cloned app appear to banks to come from a fresh, unrecognized, malware-free device, weakening the link between malware signals detected in the personal profile and fraudulent transactions (Cyber Security…
- Capabilities: Accessibility and overlay permissions (plus battery-optimization exemptions per Malwarebytes) enable screen reading, fake login overlays capturing banking credentials and the device/lock-screen PIN, automated taps and remote…
- Delivery: fake airline, tax, government and (per Cyber Security News) banking apps sideloaded via phishing sites, messaging apps and social media; Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures.
- Scope: 11 targeted countries (Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye and a GCC state) per Cyber Security News and The Hacker News; GBHackers frames it as Southeast Asia, Latin America,…
- Indonesia, Feb-Jul 2026: about 1,469 compromised devices, 1,281 potentially compromised logins (Cyber Security News, Infosecurity Magazine) and estimated losses of roughly $960,939 (GBHackers, Cyber Security News, Infosecurity Magazine;…
Coverage timelineoldest first · each row is one article
- · 6d agoGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers· 60
Group-IB says GoldFactory's Gigabud Android trojan uses Vwork, a weaponized Shelter fork, to clone banking apps into isolated Work Profiles and evade bank-side detection.
- · 6d agoHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News· 58
GoldFactory-linked Gigabud and Vwork malware clone banking apps into hidden Android work profiles to evade fraud detection across 11+ countries.
- · 6d agoGigabud Uses Android App Cloning to Evade Fraud Detection
Infosecurity Magazine· 52
Group-IB reports the Gigabud Android banking trojan clones bank apps into isolated work profiles via the Vwork tool to evade fraud detection, with roughly $960,000 in losses in Indonesia.
- · 5d agoGigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Hacker News· 60
Group-IB reports the Gigabud Android banking trojan uses a cloned work profile to hide from banking app malware checks, with infections confirmed in Indonesia.
- · 4d agoIndonesia Hit by Android Banking App-Cloning Campaign
Dark Reading· 45
GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.
- · 4d agoAndroid malware creates a hidden copy of your banking app
Malwarebytes Labs· 45
Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.