Security News

Gigabud Banking Trojan Uses Android's Work Profile Trick to Dodge Fraud Alerts

Infosecurity Magazine · 10 Sept 2026
Key Takeaway Australian SMBs and their staff should avoid installing apps from unofficial links or messages, and should treat unexpected requests for accessibility or overlay permissions on banking apps as a red flag.

Security researchers at Group-IB have identified a new technique used by the Gigabud Android banking trojan, which now works alongside a tool called Vwork to clone legitimate banking apps into a separate, hidden Android work profile. This tactic breaks the usual link between a malware infection alert and the fraudulent transaction that follows, making it much harder for banks to detect suspicious activity.

Once Gigabud infects a device (often through phishing sites, messaging apps or social media posts disguised as airline, tax or government apps) it requests accessibility access, overlay permissions and battery exemptions to take control. It then uses Vwork to clone the victim's real banking app into an isolated work profile, where fake login screens capture credentials and a hidden overlay steals the device's lock screen code. During the actual fraudulent transaction, a black screen hides the activity from the victim, and because the transaction originates from a 'new' cloned app instance, it appears to the bank as coming from an unrecognised device with no history of malware.

Group-IB confirmed the full attack chain on Indonesian devices, where between February and July 2026 it recorded around 1,469 compromised devices, 1,281 potentially compromised logins and estimated losses of about $960,939. Gigabud samples built to exploit this cloning method have also been found targeting users in Brazil, Colombia, Egypt, Mexico, Thailand and Turkiye, suggesting the technique may spread further.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.