LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
malware

Gigabud Uses Android App Cloning to Evade Fraud Detection

Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud

zeroday.news ·

The Gigabud Android banking trojan has been updated with a new technique that utilizes Android's work profile feature to clone banking applications, allowing fraudsters to bypass traditional fraud detection mechanisms. This development, attributed to the GoldFactory threat group, was detailed in research published on September 9.

The new technique involves pairing Gigabud with Vwork, a modified version of the open-source Android cloning application Shelter. While Shelter is designed for legitimate use by device owners, Vwork exposes its cloning functionalities in a way that other applications on the device can invoke them. Gigabud samples have been found to contain specific code that enables it to provision a work profile, clone a designated application, and report the successful cloning.

To facilitate the cloning process, Gigabud retrieves a token from an external authorization server. The primary objective of this method is to achieve detection isolation. Applications operating within a work profile are largely invisible to signature-based detection tools running in the personal profile. This allows attackers to install the malware, wait, then clone a banking app into the newly created work profile, and conduct transactions from there. To the bank, these transactions appear to originate from an unrecognized device without any prior malware history.

The attack chain further involves the use of fake login screens to capture banking credentials and an invisible overlay to obtain the device's lock screen code. During the fraudulent transaction, a black screen is displayed on the handset to conceal the activity from the victim.

While Gigabud samples equipped with Vwork have been observed targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye, the full infection chain has only been confirmed on devices in Indonesia. Between February and July, researchers observed approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses totaling around $960,939. These figures are considered indicative rather than fully representative of the region.

Gigabud has been active since 2022 and typically reaches victims through phishing sites, messaging applications, and social media, often disguised as legitimate applications from airlines, tax authorities, or government agencies. Upon its initial launch, the malware requests accessibility access, overlay permission, and a battery exemption. Granting accessibility access is crucial for the operators to gain control over the device.

To counter this evolving threat, banks are advised to look for several behavioral signals. These include the appearance of a work profile on a user's phone that they did not set up, matching banking app markers across both personal and work profiles, an otherwise empty isolated environment within the work profile, and an application requesting accessibility access without a clear legitimate reason. The presence of two or more of these signals should prompt a high-risk session alert. Additionally, device binding is recommended to prevent stolen login credentials from authorizing payments. Users are advised to download applications only from official app stores.

malwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]