Skip to content
Gigabud Uses Android App Cloning to Evade Fraud Detection

Gigabud Uses Android App Cloning to Evade Fraud Detection

Infosecurity-Magazine September 9, 2026

The Gigabud Android banking trojan has been equipped to clone banking apps into a separate Android work profile, giving fraudsters a way to break the link between a malware alert and the transaction that follows it.

Group-IB said in research published on September 9 that Gigabud was being paired with Vwork, a weaponized fork of the open-source Android cloning app Shelter. It attributed both to GoldFactory , concluding the group had developed or customized each.

The full infection chain was confirmed only on devices in Indonesia. Gigabud samples built to work with Vwork were found to be targeting 11 countries, among them Brazil, Colombia, Egypt, Mexico, Thailand and Turkiye.

Vwork Hides Banking Apps in Work Profiles

Vwork uses Android's Work Profile feature for app cloning into an isolated environment. Where Shelter is meant to be driven by the device owner, Group-IB said Vwork exposed its cloning functions as an interface any other app on the device could call.

Gigabud samples carried dedicated code for it, including three new commands to provision the profile, clone a named app and report back what had been cloned. Cloning requires a token from an external authorization server, which Gigabud retrieves.

Group-IB said the point is detection isolation: apps in one profile are largely invisible to signature-based detection in another, so an alert raised in the personal profile does not fire in a work profile created afterwards.

Operators install the malware, wait, then clone the bank's app into the new profile and transact from there. To the bank the payment appears to come from an unrecognized device with no malware history.

Fake login screens then capture banking credentials while a separate invisible overlay takes the lock screen code. During the fraud itself a black screen conceals what is happening on the handset.

Fraud Detection Faces a New Separation Problem

In Indonesia between February and July 2026, Group-IB observed 1469 compromised devices and 1281 potentially compromised logins, with estimated losses of roughly $960,939. It called the figures indicative rather than representative of the region.

Gigabud, active since 2022 , reaches victims through phishing sites, messengers and social media, posing as airline, tax authority or government apps. On first launch it requests accessibility access, overlay permission and a battery exemption, the first of which is where the operator gains control.

Group-IB named six behavioral signals for banks, including a work profile appearing on a phone the user never set up, matching banking app markers across profiles, an otherwise empty isolated environment and accessibility access on an app with no reason for needing it.

Two or more together should be treated as a high-risk session, said Group-IB. Its other advice was device binding to stop stolen logins authorizing payments, and for users, official stores only.

Fake anti-virus jumps from PCs to Android News 24 June 2013

Fake anti-virus jumps from PCs to Android

RedWing Android Spyware Sold as a Service on Telegram News 8 July 2026

RedWing Android Spyware Sold as a Service on Telegram

Rokarolla Trojan Combines Banking Fraud With Device Surveillance News 16 June 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

Trojanized Android App Fuels New Wave of NFC Fraud News 21 April 2026

Trojanized Android App Fuels New Wave of NFC Fraud

Financial Brands Targeted in Global Mobile Banking Malware Surge News 19 March 2026

Financial Brands Targeted in Global Mobile Banking Malware Surge

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

NCSC Warns Shadow AI Creates New Security Risks

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

Multiple Class Action Lawsuits Filed Against IDScan

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

NCSC Warns Shadow AI Creates New Security Risks

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

How to Manage Enterprise Cyber Resilience in the Age of AI

How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust