The Gigabud Android banking trojan has been updated with a new technique that utilizes Android's work profile feature to clone banking applications, allowing fraudsters to bypass traditional fraud detection mechanisms. This development, attributed to the GoldFactory threat group, was detailed in research published on September 9.
The new technique involves pairing Gigabud with Vwork, a modified version of the open-source Android cloning application Shelter. While Shelter is designed for legitimate use by device owners, Vwork exposes its cloning functionalities in a way that other applications on the device can invoke them. Gigabud samples have been found to contain specific code that enables it to provision a work profile, clone a designated application, and report the successful cloning.
To facilitate the cloning process, Gigabud retrieves a token from an external authorization server. The primary objective of this method is to achieve detection isolation. Applications operating within a work profile are largely invisible to signature-based detection tools running in the personal profile. This allows attackers to install the malware, wait, then clone a banking app into the newly created work profile, and conduct transactions from there. To the bank, these transactions appear to originate from an unrecognized device without any prior malware history.
The attack chain further involves the use of fake login screens to capture banking credentials and an invisible overlay to obtain the device's lock screen code. During the fraudulent transaction, a black screen is displayed on the handset to conceal the activity from the victim.
While Gigabud samples equipped with Vwork have been observed targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye, the full infection chain has only been confirmed on devices in Indonesia. Between February and July, researchers observed approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses totaling around $960,939. These figures are considered indicative rather than fully representative of the region.
Gigabud has been active since 2022 and typically reaches victims through phishing sites, messaging applications, and social media, often disguised as legitimate applications from airlines, tax authorities, or government agencies. Upon its initial launch, the malware requests accessibility access, overlay permission, and a battery exemption. Granting accessibility access is crucial for the operators to gain control over the device.
To counter this evolving threat, banks are advised to look for several behavioral signals. These include the appearance of a work profile on a user's phone that they did not set up, matching banking app markers across both personal and work profiles, an otherwise empty isolated environment within the work profile, and an application requesting accessibility access without a clear legitimate reason. The presence of two or more of these signals should prompt a high-risk session alert. Additionally, device binding is recommended to prevent stolen login credentials from authorizing payments. Users are advised to download applications only from official app stores.






