Researchers at
Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.
To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool
Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.
The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.
Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.
How an attack works
Victims are lured into
sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.
To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as
overlays.
The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.
Fake banking-login overlays steal both banking credentials and the device’s PIN.
The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.
The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.
This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.
How to stay safe
The immediate protection advice is familiar but important:
Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.
Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through
Malwarebytes Scam Guard.
Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.
Protection. Use an up-to-date real-time
anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.
Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.
A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.
Scammers know more about you than you think.