ZeroHour
Story · 1 source · 1 articlefirst updated ()

GoldFactory's Gigabud Android Banking Trojan Clones Banking Apps Into Hidden Work Profiles to Evade Fraud Detection

mediumMalwareexploited in the wildimportance 60
What's new: First consolidated summary for this story. Newly disclosed: Gigabud's Vwork capability (a Shelter-derived helper attributed to GoldFactory) that clones banking apps into hidden Android work profiles to evade fraud detection and signature-based malware scans, plus Group-IB's Indonesia campaign metrics for February-July 2026 (~1,469 compromised devices, 1,281 potentially compromised logins,…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Group-IB reports the Gigabud Android banking trojan, attributed to GoldFactory, uses a Shelter-derived helper called Vwork to clone victims' banking apps into hidden Android work profiles and run fraud undetected, with ~1,469 compromised devices and ~$960,939…

Group-IB research reported by Infosecurity Magazine, The Hacker News, and Malwarebytes Labs describes a new capability in Gigabud, an Android banking trojan active since 2022 and linked by Group-IB to the GoldFactory group. Gigabud now installs Vwork, a weaponized/trojanized fork of the open-source Shelter Android cloning app, which creates an Android work profile and drops a cloned (tampered) banking app inside it; Infosecurity Magazine adds that Vwork exposes its cloning functions so any installed app can call them. Victims are lured via phishing sites and messengers into sideloading fake airline, tax, or government apps, then grant Accessibility, overlay, and battery-optimization permissions. Fake login screens and overlays capture banking credentials and the device PIN, while a black screen conceals operator actions. Cloned-app transactions appear to banks as coming from an unrecognized, malware-free device, and fraud in the work profile does not trigger malware alerts configured in the personal profile. In Indonesia between February and July 2026, Group-IB counted about 1,469 compromised devices and 1,281 potentially compromised logins, with estimated losses of roughly $960,939 (The Hacker News rounds this to roughly $960,000); the full attack chain was confirmed only in Indonesia, though Vwork-enabled samples target 11 countries including Brazil, Mexico, Indonesia, Thailand, and Türkiye. Dark Reading corroborates GoldFactory's abuse of the Android Work Profile feature in Indonesia and additionally reports that the Mantax and Otax malware families are spreading through separate distribution channels, though it gives no victim counts or loss figures. Defenses: Group-IB lists six behavioral signals for banks and recommends device binding; banks are advised to watch for unexplained work profiles and unnecessary Accessibility grants, and Malwarebytes notes that a second instance of a banking app in a work profile is a strong compromise indicator (its products detect Gigabud components under multiple Android.Trojan.Banker signatures).

  • Gigabud is an Android banking trojan active since 2022, attributed by Group-IB to the GoldFactory group.
  • Gigabud installs Vwork, a weaponized/trojanized fork of the open-source Shelter cloning app, to create an Android work profile and clone the victim's banking app into it; per Infosecurity Magazine, Vwork exposes cloning functions so any…
  • The technique isolates fraud from detection: transactions from the cloned app appear to banks as coming from an unrecognized, malware-free device, and alerts in the personal profile do not fire in the work profile.
  • Distribution is via phishing sites and messengers posing as airline, tax, and government apps; victims grant Accessibility, overlay, and battery-optimization permissions, and fake login overlays steal banking credentials and the device PIN.
  • Indonesia, February-July 2026: about 1,469 compromised devices, 1,281 potentially compromised logins, and estimated losses of roughly $960,939 (The Hacker News cites roughly $960,000); the full attack chain was confirmed only in Indonesia.
  • Vwork-enabled Gigabud samples have been found targeting 11 countries, including Brazil, Mexico, Indonesia, Thailand, and Türkiye, though only the Indonesian chain is confirmed.
  • Dark Reading corroborates GoldFactory's abuse of the Android Work Profile feature in Indonesia and reports the Mantax and Otax malware families spreading through separate distribution channels; it provides no victim counts or loss figures.
  • Mitigations and indicators: Group-IB lists six behavioral signals for banks and recommends device binding; banks should watch for unexplained work profiles and unnecessary Accessibility grants; a second instance of a banking app in a work…

Coverage timeline

  1. · 7d ago
    Infosecurity Magazine· 52
    Gigabud Uses Android App Cloning to Evade Fraud Detection

    Group-IB reports the Gigabud Android banking trojan clones bank apps into isolated work profiles via the Vwork tool to evade fraud detection, with roughly $960,000 in losses in Indonesia.