Particle.news

Gigabud Uses Work Profiles to Hide Tampered Banking Apps

Group-IB says the trojan now pairs with a weaponized Shelter fork so fraud can appear to come from a clean device, a chain confirmed on phones in Indonesia.

Overview

  • Group-IB published a report on September 9 that shows Gigabud installs a second app, Vwork, which programmatically creates an Android work profile and drops a tampered banking app into it.
  • The attack wins control by asking for Accessibility, overlay and battery-exemption permissions, then uses fake login overlays, an invisible overlay to steal the lock PIN, and a black screen to hide transactions.
  • Group-IB confirmed the full Gigabud→Vwork→tampered-app chain only on devices in Indonesia, but samples built to work with Vwork were found aimed at at least 11 countries.
  • The technique defeats signature and in-app malware checks because apps inside a work profile are isolated from the personal profile, so banks should look for behavioral signs and use device binding and stronger second factors.
  • Gigabud has been active since 2022 and this case shows code reuse from the open-source Shelter tool; banks and users should expect continued evolution and should treat unexpected work profiles or duplicate banking apps as high-risk signals.