Gigabud Android Banking Trojan Hides Cloned Banking Apps in Hidden Work Profiles, Confirmed Hitting Indonesian Users
Group-IB research shows the GoldFactory-linked Gigabud Android banking trojan installs Vwork, a modified copy of the open-source Shelter tool, to create a hidden Android work profile containing a cloned/tampered banking app, letting fraud run unseen by…
Group-IB researchers report that the Gigabud Android banking trojan — active since 2022 and attributed by Group-IB to the GoldFactory group — installs a helper app called Vwork, a trojanized version of the open-source Shelter tool, which creates a hidden Android work profile and places a cloned/tampered copy of the victim's banking app inside it. This hides the trojan from banking apps' malware scans and lets operators run fraudulent transactions from the cloned app, activity that may not correlate with malware alerts in the personal profile and can potentially bypass bank-side anti-fraud checks. Victims are lured via phishing sites and messages into sideloading fake airline, tax, or government apps, then grant Accessibility, overlay, and battery-optimization permissions that enable remote control and fake login overlays stealing banking credentials and the device PIN, with a black screen concealing the operator's actions. Group-IB confirmed the full attack chain on infected devices in Indonesia, counting about 1,469 compromised devices and estimated losses of roughly $960,000 between February and July 2026; Vwork-compatible Gigabud samples have been found targeting 11 countries including Brazil, Mexico, Indonesia, Thailand, and Türkiye, though only the Indonesian infection chain is confirmed. Dark Reading independently reports GoldFactory's app-cloning campaign against Indonesian Android banking customers via Work Profile abuse and notes the Mantax and Otax malware families are spreading through separate distribution channels. Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures.
- Vwork is a modified/trojanized copy of the open-source Shelter tool that creates a hidden Android work profile hosting a cloned or tampered banking app invisible to banking apps' malware scans (Group-IB; Malwarebytes).
- Gigabud has been active since 2022 and is attributed by Group-IB to the GoldFactory group; Dark Reading also attributes the Indonesian Work Profile app-cloning campaign to GoldFactory.
- Group-IB confirmed the full attack chain in Indonesia: about 1,469 compromised devices and estimated losses of roughly $960,000 between February and July 2026.
- Vwork-compatible Gigabud samples were found targeting 11 countries, including Brazil, Mexico, Indonesia, Thailand, and Türkiye; only the Indonesian infection chain is confirmed.
- Victims are lured by phishing sites and messages into sideloading fake airline, tax, or government apps, then grant Accessibility, overlay, and battery-optimization permissions enabling remote control and fake login overlays that steal…
- Fraudulent transactions run from the cloned app in the work profile may not correlate with malware alerts in the personal profile and can potentially bypass bank-side anti-fraud checks.
- Dark Reading separately reports that the Mantax and Otax malware families are spreading through separate distribution channels.
- Detection and compromise indicators: Malwarebytes detects Gigabud under multiple Android.Trojan.Banker signatures; banks and users should watch for unexplained work profiles, unnecessary Accessibility grants, and a second instance of a…
Coverage timelineoldest first · each row is one article
- · 6d agoGigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Hacker News· 60
Group-IB reports the Gigabud Android banking trojan uses a cloned work profile to hide from banking app malware checks, with infections confirmed in Indonesia.
- · 5d agoIndonesia Hit by Android Banking App-Cloning Campaign
Dark Reading· 45
GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.
- · 5d agoAndroid malware creates a hidden copy of your banking app
Malwarebytes Labs· 45
Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.