Gigabud Banking Trojan Hides Inside Android Work Profiles to Dodge Bank Security Checks
Security researchers at Group-IB have identified a new technique used by the Gigabud banking trojan, which has been active since 2022. The malware now installs a second app that creates an Android work profile, a feature normally used to separate employer apps from personal ones, then places a tampered banking app inside that isolated space. Because the phone's genuine banking app can only scan the personal profile for known malware, the trojan effectively hides in plain sight, letting fraudulent transactions appear unconnected to any security alert already triggered on the device.
Gigabud typically reaches victims through fake apps impersonating airlines, tax offices, or government portals, distributed outside official app stores. Once installed, it requests Accessibility access along with permissions to draw over other apps and run in the background. Accessibility access is the critical step that hands the attacker remote control of the phone, allowing them to view installed apps, overlay fake login screens to steal banking credentials, and even capture the device's lock screen code. Group-IB says attackers can then carry out transactions directly on the victim's phone while a black screen hides the activity from the user.
The companion app enabling this work profile trick, called Vwork, closely resembles an open-source tool called Shelter, which is normally used by phone owners to isolate their own apps. The key difference is that Vwork automates these actions on behalf of the attacker rather than the device owner. Group-IB has confirmed this full attack chain on infected devices in Indonesia.