Gigabud Uses Android Work Profiles to Dodge Scans

Group-IB said on September 9 that the Gigabud Android banking trojan is now using a second app, Vwork, to create Android work profiles and clone banking apps inside them. The firm said it confirmed the full chain on infected devices in Indonesia, showing the campaign moving from theory to in-the-wild use. The split matters because Android keeps a work profile separate from the personal space, and Gigabud is using that separation to make a banking app’s own malware check look in the wrong place. The bank app scans one profile while the trojan sits in the other, so a fraudulent session can appear unrelated to the alert already on the phone. For banks, the exposure sits in any mobile-fraud model that trusts a single app instance or a single device view. If customer consent creates the work profile, the control surface is no longer just the banking app itself; the blind spot is the container boundary Android is designed to preserve.

Part of the PlainSec briefing for 2026-09-10

Editions

Sources