Download Privacy Needle App

Type to search

Cybersecurity

Gigabud Malware Uses Android Work Profiles to Evade Fraud Detection

Share

The Gigabud Android banking trojan has adopted a sophisticated method of cloning banking applications into isolated work profiles to circumvent fraud detection mechanisms. This technique allows fraudsters to execute illicit transactions from an environment that remains largely invisible to security software running in the device’s primary profile.

According to research from Group-IB, the malware is paired with Vwork, a malicious version of the open-source Android cloning tool Shelter. Researchers have attributed both the Gigabud trojan and Vwork to a threat group identified as GoldFactory.

The malware uses Android’s built-in work profile feature to create a separate, isolated sandbox. While the legitimate version of Shelter is designed for user-driven privacy, Vwork exposes its cloning functions as an interface that other applications on the device can trigger. Gigabud contains specific code to provision these profiles, clone targeted banking apps, and report successful deployments back to the attackers.

This isolation creates a significant blind spot for security tools. Because signature-based detection in the personal profile typically cannot scan apps within a newly created work profile, a malware alert triggered in the main environment will not prevent fraudulent activity within the cloned profile. To the bank, the transaction appears to originate from a clean device with no history of compromise.

The technical sophistication of the attack has already resulted in substantial financial losses. In Indonesia alone, between February and July 2026, researchers observed approximately 1,469 compromised devices and 1,281 potentially compromised logins, with estimated losses totalling roughly $960,939. While these figures are specific to the region, Gigabud samples have been identified targeting users in Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye.

Gigabud typically infiltrates devices through phishing campaigns on social media, messengers, and dedicated fraudulent websites. The malware often masquerades as legitimate software, such as airline, tax authority, or government applications. Once installed, the trojan requests several high-level permissions, including accessibility access, overlay permissions, and battery exemptions. The granting of accessibility access provides the attackers with significant control over the handset.

During a fraudulent session, the malware employs multiple layers of deception. Fake login screens are used to harvest banking credentials, while an invisible overlay captures the device’s lock screen code. To prevent the user from noticing the theft in real time, a black screen is often displayed over the handset during the actual fraudulent transaction.

To combat this evolving threat, security researchers suggest that financial institutions monitor for specific behavioural signals. These include the sudden appearance of a work profile that the user did not manually configure, the presence of an otherwise empty isolated environment, or a banking application requesting accessibility access without a legitimate reason.

Banks are also advised to implement device binding to prevent stolen credentials from being used to authorise payments on unauthorised hardware. For individual users, the primary defence remains adhering to official app stores and avoiding third-party software distributed through unofficial channels.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.