Gigabud Banking Trojan Exploits Android Work Profiles to Evade Detection

The Gigabud banking trojan has surfaced with a new evasion technique that exploits Android’s work profile feature to hide from banking app security checks. Security firm Group-IB disclosed the campaign on September 9, 2026, revealing how the malware creates an isolated workspace on infected phones to sidestep detection systems built into legitimate banking applications.

This development marks a significant escalation in mobile malware sophistication, as threat actors repurpose a legitimate Android enterprise feature — the work profile — to evade the very security mechanisms designed to catch them.

How the Attack Chain Works

The attack begins with Gigabud, a remote access trojan linked to a threat group called GoldFactory, which has been active since 2022. The malware typically arrives on a victim’s phone disguised as a legitimate app — a national airline, a tax office, or a government portal — distributed through sideloading outside the official Google Play Store.

On first launch, Gigabud requests three critical permissions:

  • Accessibility access — grants the operator live control over the device
  • Draw over other apps — enables overlay attacks that hide malicious activity
  • Background execution — keeps the trojan running under the guise of battery optimization

Once Accessibility access is granted, the operator gains full remote control. The trojan sends a complete list of installed apps back to its command server, identifies banking targets, and deploys fake login overlays to capture credentials. A second invisible overlay silently captures the phone’s lock screen code, giving attackers persistent access.

The Work Profile Evasion Technique

The novel element in this campaign is a second app called Vwork, which Group-IB linked to the same GoldFactory group. Vwork exploits Android’s work profile system — a feature normally reserved for enterprise device management that creates an isolated app space separate from the user’s personal profile.

Here is why this matters: banking apps contain security code that scans the phone for known malware. But that scan is confined to the profile where the banking app runs. By cloning a tampered banking app into the work profile, the trojan hides in the personal space — invisible to the security checks running in the isolated workspace.

Group-IB reported that Vwork’s architecture and class names closely match Shelter, an open-source tool designed to let users isolate or duplicate apps using work profiles. The critical difference is intent: Shelter is controlled manually by the device owner, while Vwork opens its functions to any app on the device. Security checks that prevented unauthorized apps from calling those functions were stripped out, allowing Gigabud to drive Vwork remotely.

Confirmed Attacks in Indonesia

Group-IB confirmed the complete attack chain on infected devices in Indonesia. The installation sequence followed a predictable pattern: Gigabud first, Vwork within minutes, then a tampered banking app placed inside the work profile. In the detailed case examined, the cloned app was a fake version of a real Indonesian bank’s application rather than a duplicate of the victim’s own banking app.

The scope of the campaign is significant. Between February and July 2026, Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia alone, with estimated financial losses reaching $960,000. These figures represent only what Group-IB directly observed, not the full extent of the campaign.

Global Reach and Active Development

Gigabud samples designed to work with Vwork have been identified targeting users in multiple countries, including:

  • Brazil
  • Colombia
  • Egypt
  • Indonesia
  • Laos
  • Mexico
  • Morocco
  • The Philippines
  • Thailand
  • Türkiye
  • One unnamed Gulf Cooperation Council country

While samples have been found targeting all these regions, confirmed infections with the full Vwork chain have only been documented in Indonesia. Group-IB analyzed a single Vwork sample and described it as still under active development, with some functions proving unstable on Android builds close to the open-source version.

Why This Matters for Mobile Security

This campaign illustrates a troubling trend in mobile malware: attackers are increasingly weaponizing legitimate operating system features rather than relying on traditional exploit techniques. The work profile is an Android feature designed for enterprise security and app isolation — but in the hands of a sophisticated threat actor, it becomes a cloaking mechanism.

The implications extend beyond Gigabud specifically. Any banking trojan that can gain Accessibility access and sideload additional apps could theoretically replicate this technique. The fact that Vwork is based on an open-source tool means the underlying framework is publicly available, lowering the barrier for other threat groups to adopt similar strategies.

Protecting Against Work Profile Abuse

Android users can check for unauthorized work profiles in their phone’s settings. Google provides guidance for locating and deleting work profiles, which appears as a separate section in the Settings app under accounts or work profiles. If a work profile exists that the user did not create through their employer, it should be removed immediately.

Additional protective measures include:

  • Avoid sideloading apps from unverified sources outside the Google Play Store
  • Never grant Accessibility access to apps that do not have a clear, legitimate need for it
  • Monitor permission requests carefully, especially for banking or government-related apps installed from third-party sources
  • Enable Google Play Protect and keep it active for real-time malware scanning
  • Check for unexpected work profiles in Android settings if you notice unusual app behavior

The Broader Threat Landscape

The Gigabud campaign emerges amid a broader surge in mobile banking trojan activity throughout 2026. Threat groups are increasingly targeting Android devices in developing markets where mobile banking adoption is growing rapidly but security awareness may lag. The combination of social engineering, legitimate feature abuse, and multi-stage malware deployment represents an evolution in how financial cybercrime operates on mobile platforms.

Group-IB linked both Gigabud and Vwork to GoldFactory based on shared code references, overlapping network indicators, and developer logs written in Chinese. The organization said it could not publish all technical indicators due to ongoing investigations, suggesting the campaign may be larger than what is currently visible.

For financial institutions, the Gigabud technique highlights a gap in app-based security models. Banking apps that rely solely on scanning the current profile for malware cannot detect threats hiding in a separate profile on the same device. This may prompt banks to reconsider their in-app security architectures and explore cross-profile detection methods in future app updates.

As mobile banking continues to expand globally, particularly in Southeast Asia and Latin America, campaigns like Gigabud demonstrate that threat actors are investing heavily in circumventing the security measures that banks and platform vendors have put in place. The use of work profiles as an evasion tool is a reminder that any operating system feature can be repurposed by determined adversaries.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading