Overview
- Group-IB published a report on September 9 that shows Gigabud installs a second app, Vwork, which programmatically creates an Android work profile and drops a tampered banking app into it.
- The attack wins control by asking for Accessibility, overlay and battery-exemption permissions, then uses fake login overlays, an invisible overlay to steal the lock PIN, and a black screen to hide transactions.
- Group-IB confirmed the full Gigabud→Vwork→tampered-app chain only on devices in Indonesia, but samples built to work with Vwork were found aimed at at least 11 countries.
- The technique defeats signature and in-app malware checks because apps inside a work profile are isolated from the personal profile, so banks should look for behavioral signs and use device binding and stronger second factors.
- Gigabud has been active since 2022 and this case shows code reuse from the open-source Shelter tool; banks and users should expect continued evolution and should treat unexpected work profiles or duplicate banking apps as high-risk signals.