Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical PaperCut Flaws Exploited: 440 Servers Compromised Worldwide
September 9, 2026
Critical MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
September 9, 2026
Fake LinkedIn Job Offers Infect Developers With New RATs
September 9, 2026
Home/Threats/Android Malware Clones Banking Apps in Work Profiles to Evade Detection
Threats

Android Malware Clones Banking Apps in Work Profiles to Evade Detection

Key Takeaways A new Android banking fraud technique leverages malware to clone legitimate banking applications into hidden “work profiles” on victim devices. This method, linked to the...

Sarah simpson
Sarah simpson
September 9, 2026 4 Min Read
3 0

Key Takeaways

  • A new Android banking fraud technique leverages malware to clone legitimate banking applications into hidden “work profiles” on victim devices.
  • This method, linked to the GoldFactory threat actor and using the Gigabud trojan and Vwork app cloner, allows attackers to bypass traditional fraud detection systems.
  • The malware exploits Android’s work profile isolation feature to create a seemingly “clean” environment for fraudulent transactions, masking malicious activity.
  • Impacted regions include countries in Southeast Asia, Latin America, and North Africa, with significant financial losses observed in Indonesia.
  • Users should strictly install apps from official sources and exercise caution with accessibility requests, while financial institutions need advanced behavioral detection.

A sophisticated new Android banking fraud scheme has emerged, where attackers are employing malware to replicate legitimate banking applications within hidden “work profiles” on compromised devices. This tactic effectively isolates the fraudulent session from existing security alerts on the phone, allowing threat actors to evade detection.

Table Of Content

  • Key Takeaways
  • The Gigabud and Vwork Attack Chain
  • Evading Detection with Work Profiles
  • Observed Impact and Financial Losses
  • What You Should Do

The Gigabud and Vwork Attack Chain

The campaign initiates with the deployment of Gigabud, an Android remote-access trojan that has been active since 2022. Victims are typically targeted through deceptive phishing websites, messaging applications, or social media posts, which trick them into sideloading malicious applications disguised as legitimate airline, tax, or government services. In some cases, direct downloads of fake banking apps are used to compromise users.

Once Gigabud gains a foothold, it requests extensive permissions, including Accessibility access, the ability to draw over other applications, and exemption from battery optimization. These permissions grant the attackers remote control over the device, enabling them to enumerate installed applications, superimpose fake login screens over authentic banking apps, and even capture the device’s lock-screen credentials.

Following the initial compromise, Group-IB analysts discovered the rapid deployment of Vwork, a customized version of the open-source Shelter app cloner. Vwork is installed just minutes after the Gigabud infection, alongside manipulated banking applications. The researchers attribute this activity to the GoldFactory threat group, identifying compatible samples targeting users in Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and a Gulf Cooperation Council member state.

Evading Detection with Work Profiles

The core innovation of this attack lies in the use of Android’s work profile feature. Android’s architecture is designed to keep applications within separate profiles isolated, primarily to protect corporate and personal data. However, attackers are subverting this mechanism to make their illicit banking sessions appear legitimate.

After Vwork is installed, it creates an isolated work profile and then clones a targeted banking application into this new environment. In a documented case from Indonesia, the cloned application was a counterfeit version of a bank’s official app. Because the work profile is distinct from the personal profile, any security alerts or malware indicators associated with the personal profile may not propagate to the cloned application within the work profile. This allows the threat actor to conduct fraudulent transactions through a seemingly “clean” profile, often while displaying a black screen to the victim to conceal their actions.

This method can mislead bank fraud detection systems, as the transaction may originate from what appears to be a new, unflagged device environment, thereby weakening the link between the device’s actual risk posture and a fraudulent transfer. Similar hidden remote-control Android attacks have demonstrated how control features can be concealed from victims.

Vwork is designed to minimize its visible footprint. Its launcher icon is hidden, and its cloning capabilities are remotely controlled by another application, specifically Gigabud. The presence of commands within Gigabud to initialize Vwork, clone applications, and upload lists of cloned apps clearly indicates a coordinated design between these two malicious tools.

Observed Impact and Financial Losses

Group-IB said in a report that their researchers observed substantial activity between February and July 2026. In Indonesia alone, approximately 1,469 devices were compromised, leading to 1,281 potentially compromised logins and estimated losses totaling roughly $960,939. These figures represent only the observed activity and do not encompass the full scale of the operation, underscoring the persistent threat posed by Android banking trojan campaigns.

What You Should Do

  • For Users:
    • Only download and install applications from official app stores (Google Play Store). Avoid sideloading apps from third-party websites, messaging apps, or social media links.
    • Be extremely cautious about granting Accessibility Service permissions to any application, especially those not designed as legitimate accessibility tools.
    • Enable multi-factor authentication (MFA) for all banking and financial accounts. Prioritize authenticator apps or hardware tokens over SMS-based MFA, which can be intercepted.
    • Regularly review app permissions on your device and revoke any suspicious or unnecessary access.
    • If your phone unexpectedly creates a work profile or you notice duplicate banking apps, immediately investigate and consider a factory reset.
  • For Financial Institutions:
    • Implement robust fraud detection systems that analyze behavioral patterns beyond simple device or session identifiers.
    • Bind customer logins to trusted devices and monitor for unusual session activities, such as logins from new or unrecognized device profiles.
    • Develop detection mechanisms for unexpected work profile creation on consumer devices and flag banking applications installed across multiple profiles.
    • Integrate security signals related to active Accessibility access with transaction monitoring to block high-risk transactions.
    • Enhance detection strategies to combine static malware signatures with dynamic behavioral analysis to identify sophisticated attacks that blend legitimate Android features with malicious intent.
    • Educate customers about the dangers of sideloading apps, phishing, and granting excessive permissions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Autonomous AI Agents Launch Mass Credential Theft Attacks

Next Post

CISA Warns of Critical N-able N-central RCE Vulnerability Exploited in Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Enhances Windows Family Safety With Age Verification, Parental Controls
September 9, 2026
Critical ArangoDB Flaws Allow Auth Bypass, RCE as Root
September 9, 2026
Microsoft Teams Android Flaw Exposes Sensitive User Data
September 9, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us