ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

Gigabud Android Banking Trojan Hides Cloned Banking Apps in Hidden Work Profiles, Confirmed Hitting Indonesian Users

mediumMalwareexploited in the wildimportance 60
What's new: None — this is the first merged summary for this story. Newly disclosed: Gigabud's Vwork-based hidden work-profile technique, the confirmed Indonesian campaign with ~1,469 compromised devices and ~$960,000 in losses (Feb-Jul 2026), and the separate spread of the Mantax and Otax malware families.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Group-IB research shows the GoldFactory-linked Gigabud Android banking trojan installs Vwork, a modified copy of the open-source Shelter tool, to create a hidden Android work profile containing a cloned/tampered banking app, letting fraud run unseen by…

Group-IB researchers report that the Gigabud Android banking trojan — active since 2022 and attributed by Group-IB to the GoldFactory group — installs a helper app called Vwork, a trojanized version of the open-source Shelter tool, which creates a hidden Android work profile and places a cloned/tampered copy of the victim's banking app inside it. This hides the trojan from banking apps' malware scans and lets operators run fraudulent transactions from the cloned app, activity that may not correlate with malware alerts in the personal profile and can potentially bypass bank-side anti-fraud checks. Victims are lured via phishing sites and messages into sideloading fake airline, tax, or government apps, then grant Accessibility, overlay, and battery-optimization permissions that enable remote control and fake login overlays stealing banking credentials and the device PIN, with a black screen concealing the operator's actions. Group-IB confirmed the full attack chain on infected devices in Indonesia, counting about 1,469 compromised devices and estimated losses of roughly $960,000 between February and July 2026; Vwork-compatible Gigabud samples have been found targeting 11 countries including Brazil, Mexico, Indonesia, Thailand, and Türkiye, though only the Indonesian infection chain is confirmed. Dark Reading independently reports GoldFactory's app-cloning campaign against Indonesian Android banking customers via Work Profile abuse and notes the Mantax and Otax malware families are spreading through separate distribution channels. Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures.

  • Vwork is a modified/trojanized copy of the open-source Shelter tool that creates a hidden Android work profile hosting a cloned or tampered banking app invisible to banking apps' malware scans (Group-IB; Malwarebytes).
  • Gigabud has been active since 2022 and is attributed by Group-IB to the GoldFactory group; Dark Reading also attributes the Indonesian Work Profile app-cloning campaign to GoldFactory.
  • Group-IB confirmed the full attack chain in Indonesia: about 1,469 compromised devices and estimated losses of roughly $960,000 between February and July 2026.
  • Vwork-compatible Gigabud samples were found targeting 11 countries, including Brazil, Mexico, Indonesia, Thailand, and Türkiye; only the Indonesian infection chain is confirmed.
  • Victims are lured by phishing sites and messages into sideloading fake airline, tax, or government apps, then grant Accessibility, overlay, and battery-optimization permissions enabling remote control and fake login overlays that steal…
  • Fraudulent transactions run from the cloned app in the work profile may not correlate with malware alerts in the personal profile and can potentially bypass bank-side anti-fraud checks.
  • Dark Reading separately reports that the Mantax and Otax malware families are spreading through separate distribution channels.
  • Detection and compromise indicators: Malwarebytes detects Gigabud under multiple Android.Trojan.Banker signatures; banks and users should watch for unexplained work profiles, unnecessary Accessibility grants, and a second instance of a…

Coverage timeline

  1. · 6d ago
    The Hacker News· 60
    Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

    Group-IB reports the Gigabud Android banking trojan uses a cloned work profile to hide from banking app malware checks, with infections confirmed in Indonesia.

  2. · 5d ago
    Dark Reading· 45
    Indonesia Hit by Android Banking App-Cloning Campaign

    GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.

  3. · 5d ago
    Malwarebytes Labs· 45
    Android malware creates a hidden copy of your banking app

    Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.