The Gigabud Android banking Trojan can create a separate work profile and place a cloned banking app inside it, according to researchers at Group-IB. People who install apps from phishing links are at risk of stolen credentials and fraudulent transactions that may be harder for security systems to connect to the original infection.
Gigabud asks for Accessibility access, permission to appear over other apps and an exemption from battery optimization. These powerful permissions support remote control and fake login screens that steal banking credentials and the phone’s PIN.
Work profiles normally separate business apps and data from personal content. Group-IB found that this isolation may weaken anti-fraud or malware-detection systems that do not connect an alert in the personal profile with a transaction in the work profile.
This does not mean Android work profiles are inherently malicious or that all protection on the phone is disabled. A work profile can be legitimate, but an unexplained second copy of a banking app deserves immediate investigation.
How victims get infected
The attack starts when someone is persuaded to sideload an APK—an Android app installation file—from a phishing site, message or social media post. The malicious app may pretend to come from an airline, tax office or government agency.Gigabud asks for Accessibility access, permission to appear over other apps and an exemption from battery optimization. These powerful permissions support remote control and fake login screens that steal banking credentials and the phone’s PIN.
A second profile conceals the fraud
The attackers install Vwork, a malicious modification of the legitimate open-source Shelter tool. It creates an Android work profile, clones a selected banking app and lets the operator control that copy remotely.Work profiles normally separate business apps and data from personal content. Group-IB found that this isolation may weaken anti-fraud or malware-detection systems that do not connect an alert in the personal profile with a transaction in the work profile.
This does not mean Android work profiles are inherently malicious or that all protection on the phone is disabled. A work profile can be legitimate, but an unexplained second copy of a banking app deserves immediate investigation.
Steps Android users should take
- Install banking and other sensitive apps only from the official app store or a verified link on the publisher’s website.
- Reject unsolicited requests to install APK files, especially apps sent through messages, social media or unfamiliar websites.
- Do not grant Accessibility or “display over other apps” permission to supposed airline, delivery, tax or government apps.
- Check Android’s work-profile area for an unexpected second copy of your banking app. A work profile alone is not proof of infection, but a cloned banking app is suspicious.