MalwareTips News Gigabud Trojan hides cloned banking apps in Android work profiles

Where do you usually install Android apps from?

  • Only the official app store

    Votes: 1 100.0%
  • The store and trusted publisher sites

    Votes: 0 0.0%
  • Sometimes links or APK files

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%
  • I do not use Android

    Votes: 0 0.0%

  • Total voters
    1

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
11
35
1
The Gigabud Android banking Trojan can create a separate work profile and place a cloned banking app inside it, according to researchers at Group-IB. People who install apps from phishing links are at risk of stolen credentials and fraudulent transactions that may be harder for security systems to connect to the original infection.


How victims get infected​

The attack starts when someone is persuaded to sideload an APK—an Android app installation file—from a phishing site, message or social media post. The malicious app may pretend to come from an airline, tax office or government agency.

Gigabud asks for Accessibility access, permission to appear over other apps and an exemption from battery optimization. These powerful permissions support remote control and fake login screens that steal banking credentials and the phone’s PIN.

A second profile conceals the fraud​

The attackers install Vwork, a malicious modification of the legitimate open-source Shelter tool. It creates an Android work profile, clones a selected banking app and lets the operator control that copy remotely.

Work profiles normally separate business apps and data from personal content. Group-IB found that this isolation may weaken anti-fraud or malware-detection systems that do not connect an alert in the personal profile with a transaction in the work profile.

This does not mean Android work profiles are inherently malicious or that all protection on the phone is disabled. A work profile can be legitimate, but an unexplained second copy of a banking app deserves immediate investigation.

Steps Android users should take​

  • Install banking and other sensitive apps only from the official app store or a verified link on the publisher’s website.
  • Reject unsolicited requests to install APK files, especially apps sent through messages, social media or unfamiliar websites.
  • Do not grant Accessibility or “display over other apps” permission to supposed airline, delivery, tax or government apps.
  • Check Android’s work-profile area for an unexpected second copy of your banking app. A work profile alone is not proof of infection, but a cloned banking app is suspicious.