Particle.news

Android Trojan Uses Work Profiles to Hide Cloned Banking Apps

Security firm Group-IB says the pairing lets operators run tampered bank apps in a separate profile so fraud can appear unrelated to malware alerts.

Overview

  • Group-IB published its findings on September 9 reporting that the Gigabud trojan now installs a second app called Vwork to create an Android work profile and run a cloned or tampered banking app inside it.
  • Gigabud first gains control by tricking victims into sideloading a fake app and asking for Accessibility, overlay, and battery-exemption permissions so operators can capture credentials, steal the device PIN with overlays, and remotely perform transactions while a black screen hides activity.
  • Vwork is a weaponized fork of the open-source Shelter tool that exposes functions to programmatically set up profiles, clone apps, list contents, and open apps, and Group-IB links both tools to a threat cluster it calls GoldFactory based on shared code and network traces.
  • The full infection chain is confirmed only on devices in Indonesia where Group-IB observed activity between February and July 2026 that included about 1,469 compromised devices, 1,281 potentially exposed logins, and estimated losses near $961,000.
  • Researchers warn that Android profile isolation can defeat in-app malware checks so banks should monitor behavioral signs such as an unexpected work profile or a cloned banking app and require stronger device binding and non-SMS two-factor methods while users should avoid sideloading and refuse Accessibility access to unknown apps.