Back Infosecurity-Magazine Gigabud Uses Android App Cloning to Evade Fraud Detection
The Gigabud Android banking trojan has been equipped to clone banking apps into a separate Android work profile, giving fraudsters a way to break the link between a malware alert and the transaction that follows it.
Group-IB said in research published on September 9 that Gigabud was being paired with Vwork, a weaponized fork of the open-source Android cloning app Shelter. It attributed both to GoldFactory , concluding the group had developed or customized each.
The full infection chain was confirmed only on devices in Indonesia. Gigabud samples built to work with Vwork were found to be targeting 11 countries, among them Brazil, Colombia, Egypt, Mexico, Thailand and Turkiye.
Vwork Hides Banking Apps in Work Profiles
Vwork uses Android's Work Profile feature for app cloning into an isolated environment. Where Shelter is meant to be driven by the device owner, Group-IB said Vwork exposed its cloning functions as an interface any other app on the device could call.
Gigabud samples carried dedicated code for it, including three new commands to provision the profile, clone a named app and report back what had been cloned. Cloning requires a token from an external authorization server, which Gigabud retrieves.
Group-IB said the point is detection isolation: apps in one profile are largely invisible to signature-based detection in another, so an alert raised in the personal profile does not fire in a work profile created afterwards.
Operators install the malware, wait, then clone the bank's app into the new profile and transact from there. To the bank the payment appears to come from an unrecognized device with no malware history.
Fake login screens then capture banking credentials while a separate invisible overlay takes the lock screen code. During the fraud itself a black screen conceals what is happening on the handset.
Fraud Detection Faces a New Separation Problem
In Indonesia between February and July 2026, Group-IB observed 1469 compromised devices and 1281 potentially compromised logins, with estimated losses of roughly $960,939. It called the figures indicative rather than representative of the region.
Gigabud, active since 2022 , reaches victims through phishing sites, messengers and social media, posing as airline, tax authority or government apps. On first launch it requests accessibility access, overlay permission and a battery exemption, the first of which is where the operator gains control.
Group-IB named six behavioral signals for banks, including a work profile appearing on a phone the user never set up, matching banking app markers across profiles, an otherwise empty isolated environment and accessibility access on an app with no reason for needing it.
Two or more together should be treated as a high-risk session, said Group-IB. Its other advice was device binding to stop stolen logins authorizing payments, and for users, official stores only.
Fake anti-virus jumps from PCs to Android News 24 June 2013
Fake anti-virus jumps from PCs to Android
RedWing Android Spyware Sold as a Service on Telegram News 8 July 2026
RedWing Android Spyware Sold as a Service on Telegram
Rokarolla Trojan Combines Banking Fraud With Device Surveillance News 16 June 2026
Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Trojanized Android App Fuels New Wave of NFC Fraud News 21 April 2026
Trojanized Android App Fuels New Wave of NFC Fraud
Financial Brands Targeted in Global Mobile Banking Malware Surge News 19 March 2026
Financial Brands Targeted in Global Mobile Banking Malware Surge
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
NCSC Warns Shadow AI Creates New Security Risks
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Multiple Class Action Lawsuits Filed Against IDScan
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
NCSC Warns Shadow AI Creates New Security Risks
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How to Manage Enterprise Cyber Resilience in the Age of AI
How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
