www.group-ib.com
Gigabud Trojan Leverages Vwork for Banking App Cloning
Article Content
The Gigabud Android banking trojan, active since 2022, has been found using Vwork, a modified version of the open-source app Shelter, to clone banking applications into a separate Android work profile. This method allows fraudsters to evade detection by isolating malicious activity from legitimate transactions. Group-IB's research indicates that Gigabud is targeting users in Southeast Asia, South Asia, the Middle East, Africa, and Latin America, with confirmed infections in Indonesia. The malware is delivered through phishing sites and impersonates trusted entities like airlines and government agencies. In Indonesia alone, 1,469 devices were compromised, leading to estimated losses of approximately $960,939. Vwork's API allows for automated cloning of banking apps, making detection more challenging for security systems. The attack chain has been confirmed in multiple regions, with specific Gigabud samples designed to operate with Vwork. Group-IB has issued recommendations for banks to identify suspicious activity linked to this threat.
Key Points: • Gigabud uses Vwork to clone banking apps, enhancing evasion tactics. • Confirmed infections in Indonesia with significant financial losses reported. • Targeting multiple regions, including Southeast Asia and Latin America.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.