Incident
Published 2026-09-09
Verified 2026-09-19

Gigabud Android banking trojan clones apps via Vwork work-profile (Group-IB)

Group-IB (9 September 2026) documents a Gigabud (GoldFactory) banking-trojan chain that installs a second Android app, Vwork, to create a work profile and drop a tampered banking app inside it. Work-profile isolation hides the trojan from the banking app’s malware checks on the personal profile. Confirmed on infected devices in Indonesia. Gigabud arrives as a sideloaded fake airline/tax/government app, demands Accessibility and overlay permissions, overlays fake logins and lock-screen capture, then drives taps via Accessibility under a black screen. Vwork is based on open-source Shelter but strips caller checks so other apps can create profiles, clone apps, and open them; setup is reduced to a single Chinese-language prompt. Order observed: Gigabud → Vwork within minutes → cloned banking app. Distinct from desk card mantax-otax-android-20260910. Primary: Group-IB; wire: The Hacker News (10 Sep 2026).

Product
Android (Gigabud RAT / Vwork work-profile helper)
Versions
n/a (malware; sideloaded outside Play)
Exploited in Australia?
unknown
Patch to
Avoid sideloaded “gov/airline/tax” APKs; deny Accessibility to untrusted apps; remove unknown work profiles; reset device if compromise suspected

Primary: Group-IB — Vwork app cloning / Gigabud (9 Sep 2026) · The Hacker News (10 Sep 2026)

breaches identity