ZeroHour
Story · 1 source · 1 articlefirst updated ()

GoldFactory's Gigabud Android Trojan Clones Banking Apps Into Hidden Work Profiles to Evade Fraud Detection

mediumMalwareexploited in the wildimportance 60
What's new: First merged story on this campaign (no prior dashboard entry). Key developments reported: (1) Gigabud has added dedicated code to drive Vwork, extending its known behavior since 2022 with work-profile app cloning; (2) the technique shifts fraud into a cloned banking app inside a hidden work profile so banks see a fresh, apparently malware-free device; (3) targeting spans 11 countries, but only…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Group-IB links the Gigabud Android banking trojan to the GoldFactory group and a weaponized Shelter fork called Vwork, which clones victims' banking apps into hidden Android work profiles so fraud looks like clean device activity; ~1,469 compromised devices…

Group-IB attributes an Android app-cloning campaign to the GoldFactory threat group, whose Gigabud banking trojan (active since 2022) now ships dedicated code for Vwork, a modified/weaponized fork of the open-source Shelter app cloner. Vwork hides its launcher icon and exposes cloning functions so any installed app can call them, letting operators drop a tampered copy of the victim's banking app into an isolated Android work profile. Transactions from the cloned app appear to banks as coming from an unrecognized, malware-free device, weakening device-risk signals tied to malware in the personal profile, and alerts in the personal profile do not fire in the work profile. Victims are lured via phishing sites, messaging apps and social media into sideloading fake airline, tax, government (and, per one report, banking) apps, then grant Accessibility and overlay permissions — plus battery-optimization exemptions — enabling remote control and fake login overlays that steal credentials and device PIN/lock-screen codes, with a black screen concealing operator actions. Between February and July 2026, Group-IB observed about 1,469 compromised devices, 1,281 potentially compromised logins and estimated losses of roughly $960,939 in Indonesia — the only country where the full attack chain is confirmed — while Vwork-enabled Gigabud samples target 11 countries. Dark Reading separately notes Mantax and Otax malware spreading through separate distribution channels; its article cites no victim counts or loss figures. Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures.

  • Attribution: Group-IB links Gigabud (active since 2022) to the GoldFactory group.
  • Tooling: Vwork is a modified/trojanized fork of the open-source Shelter app cloner; it hides its launcher icon and exposes cloning functions so any installed app can invoke them.
  • Technique: the victim's banking app is cloned into a hidden, isolated Android work profile, so fraudulent sessions look clean to bank-side fraud/device-risk checks and signature-based detection in the personal profile does not trigger.
  • Permissions abused: Accessibility, overlay (and battery-optimization exemptions per Malwarebytes) enable remote device control; fake login screens/overlays capture credentials and the device PIN or lock-screen code.
  • Delivery: sideloading of fake airline, tax, government (and per Cyber Security News, banking) apps pushed via phishing sites, messaging apps and social media.
  • Indonesia impact, Feb-Jul 2026: ~1,469 compromised devices, 1,281 potentially compromised logins, estimated losses ~$960,939; full attack chain confirmed only in Indonesia (Report 3 rounds losses to ~$960,000).
  • Geographic scope: Vwork-enabled samples target 11 countries — Brazil, Colombia, Egypt, Indonesia, Mexico, Morocco, the Philippines, Thailand, Turkiye, Laos and a GCC state; only the Indonesian chain is confirmed.
  • Guidance: Group-IB lists six behavioral signals for banks and recommends device binding; other recommendations include official app stores only, refusing broad Accessibility grants, non-SMS second factors, and flagging unexpected…

Coverage timeline

  1. · 7d ago
    Cyber Security News· 58
    Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection

    GoldFactory-linked Gigabud and Vwork malware clone banking apps into hidden Android work profiles to evade fraud detection across 11+ countries.