Malware News Android malware creates a hidden copy of your banking app

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,116
6,076
2,168
Germany
Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.

Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.

How an attack works​

Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.

The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.

Fake banking-login overlays steal both banking credentials and the device’s PIN.

The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.

The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.

This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.

How to stay safe​

The immediate protection advice is familiar but important:

Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.

Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.

Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.

Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.

Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.

A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.


Scammers know more about you than you think.
 
  • Like
Reactions: Parkinsond


Hi, the important point is that the work profile is not the initial breach—it is a concealment and fraud technique used after the victim has sideloaded the malicious app and granted powerful permissions. Avoiding untrusted APKs and refusing implausible Accessibility requests breaks the described attack chain early.

What this changes in practice​

Profile isolation is normally a security feature, but here it can also prevent apps in the personal profile from seeing enough context inside the work profile. That does not make Android work profiles inherently unsafe, nor does it mean that simply viewing a phishing page creates a hidden banking copy.

The sequence matters:

  1. A malicious APK is installed.
  2. The victim grants Accessibility and other special access.
  3. The malware gains remote-control and credential-theft capabilities.
  4. A work profile and cloned banking app are then used to conduct or disguise fraud.

So the cloned app is a later-stage symptom of a device already under substantial control. Malware does love turning legitimate administration features into decidedly unofficial administration features.

Signs worth checking​

A work profile alone is normal on employer-managed phones and for people intentionally using tools such as Shelter. More meaningful warning signs are:

  • an unexpected Work section in the app drawer or settings;
  • a second banking-app icon carrying a work-profile badge;
  • an unfamiliar device-policy or profile-management app;
  • Accessibility, overlay, device-admin or unrestricted battery access granted to an unexpected app;
  • unexplained screen blackouts or remote-looking interaction.

A duplicate banking app is highly suspicious if the owner or their employer did not create that profile, but the icon by itself does not identify Gigabud specifically.

If the APK was installed and permissions were granted​

Treat that as a possible account compromise rather than relying on an antivirus result alone.

  1. From a separate trusted device, contact the bank using its official app, website or the number printed on the card. Review transactions and ask the bank to secure online access.
  2. Change banking credentials and any reused password. Revoke other sessions or registered devices where the service provides that option, verify recovery details, and enable MFA.
  3. On the affected phone, disconnect it from networks if remote activity appears to be continuing. Do not use it for banking or password changes.
  4. Preserve only known-good personal data such as photos and documents. Avoid backing up APKs, app settings or a suspicious device configuration.
  5. A factory reset is the prudent recovery choice after this level of access. Set the phone up cleanly, install current system updates, and reinstall apps only from trusted official sources rather than restoring everything indiscriminately.

Anyone needing individualized diagnosis or cleanup before resetting should use MalwareTips’ Malware Removal Assistance team. Removing the visible APK or work profile may stop one component, but it does not establish that credentials and active sessions remain safe.
 
The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.
Good luck with good banking apps, which send instant notifications even about changed settings via app or email.

IMG_20260911_173835063_HDR.jpg
 
  • Like
Reactions: Jonny Quest