Android Malware Clones Banking Apps in Work Profiles to Evade Detection
Key Takeaways A new Android banking fraud technique leverages malware to clone legitimate banking applications into hidden “work profiles” on victim devices. This method, linked to the...
Key Takeaways
- A new Android banking fraud technique leverages malware to clone legitimate banking applications into hidden “work profiles” on victim devices.
- This method, linked to the GoldFactory threat actor and using the Gigabud trojan and Vwork app cloner, allows attackers to bypass traditional fraud detection systems.
- The malware exploits Android’s work profile isolation feature to create a seemingly “clean” environment for fraudulent transactions, masking malicious activity.
- Impacted regions include countries in Southeast Asia, Latin America, and North Africa, with significant financial losses observed in Indonesia.
- Users should strictly install apps from official sources and exercise caution with accessibility requests, while financial institutions need advanced behavioral detection.
A sophisticated new Android banking fraud scheme has emerged, where attackers are employing malware to replicate legitimate banking applications within hidden “work profiles” on compromised devices. This tactic effectively isolates the fraudulent session from existing security alerts on the phone, allowing threat actors to evade detection.
Table Of Content
The Gigabud and Vwork Attack Chain
The campaign initiates with the deployment of Gigabud, an Android remote-access trojan that has been active since 2022. Victims are typically targeted through deceptive phishing websites, messaging applications, or social media posts, which trick them into sideloading malicious applications disguised as legitimate airline, tax, or government services. In some cases, direct downloads of fake banking apps are used to compromise users.
Once Gigabud gains a foothold, it requests extensive permissions, including Accessibility access, the ability to draw over other applications, and exemption from battery optimization. These permissions grant the attackers remote control over the device, enabling them to enumerate installed applications, superimpose fake login screens over authentic banking apps, and even capture the device’s lock-screen credentials.
Following the initial compromise, Group-IB analysts discovered the rapid deployment of Vwork, a customized version of the open-source Shelter app cloner. Vwork is installed just minutes after the Gigabud infection, alongside manipulated banking applications. The researchers attribute this activity to the GoldFactory threat group, identifying compatible samples targeting users in Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and a Gulf Cooperation Council member state.
Evading Detection with Work Profiles
The core innovation of this attack lies in the use of Android’s work profile feature. Android’s architecture is designed to keep applications within separate profiles isolated, primarily to protect corporate and personal data. However, attackers are subverting this mechanism to make their illicit banking sessions appear legitimate.
After Vwork is installed, it creates an isolated work profile and then clones a targeted banking application into this new environment. In a documented case from Indonesia, the cloned application was a counterfeit version of a bank’s official app. Because the work profile is distinct from the personal profile, any security alerts or malware indicators associated with the personal profile may not propagate to the cloned application within the work profile. This allows the threat actor to conduct fraudulent transactions through a seemingly “clean” profile, often while displaying a black screen to the victim to conceal their actions.
This method can mislead bank fraud detection systems, as the transaction may originate from what appears to be a new, unflagged device environment, thereby weakening the link between the device’s actual risk posture and a fraudulent transfer. Similar hidden remote-control Android attacks have demonstrated how control features can be concealed from victims.
Vwork is designed to minimize its visible footprint. Its launcher icon is hidden, and its cloning capabilities are remotely controlled by another application, specifically Gigabud. The presence of commands within Gigabud to initialize Vwork, clone applications, and upload lists of cloned apps clearly indicates a coordinated design between these two malicious tools.
Observed Impact and Financial Losses
Group-IB said in a report that their researchers observed substantial activity between February and July 2026. In Indonesia alone, approximately 1,469 devices were compromised, leading to 1,281 potentially compromised logins and estimated losses totaling roughly $960,939. These figures represent only the observed activity and do not encompass the full scale of the operation, underscoring the persistent threat posed by Android banking trojan campaigns.
What You Should Do
- For Users:
- Only download and install applications from official app stores (Google Play Store). Avoid sideloading apps from third-party websites, messaging apps, or social media links.
- Be extremely cautious about granting Accessibility Service permissions to any application, especially those not designed as legitimate accessibility tools.
- Enable multi-factor authentication (MFA) for all banking and financial accounts. Prioritize authenticator apps or hardware tokens over SMS-based MFA, which can be intercepted.
- Regularly review app permissions on your device and revoke any suspicious or unnecessary access.
- If your phone unexpectedly creates a work profile or you notice duplicate banking apps, immediately investigate and consider a factory reset.
- For Financial Institutions:
- Implement robust fraud detection systems that analyze behavioral patterns beyond simple device or session identifiers.
- Bind customer logins to trusted devices and monitor for unusual session activities, such as logins from new or unrecognized device profiles.
- Develop detection mechanisms for unexpected work profile creation on consumer devices and flag banking applications installed across multiple profiles.
- Integrate security signals related to active Accessibility access with transaction monitoring to block high-risk transactions.
- Enhance detection strategies to combine static malware signatures with dynamic behavioral analysis to identify sophisticated attacks that blend legitimate Android features with malicious intent.
- Educate customers about the dangers of sideloading apps, phishing, and granting excessive permissions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.