Gigabud Android banking trojan clones apps via Vwork work-profile (Group-IB)
Group-IB (9 September 2026) documents a Gigabud (GoldFactory) banking-trojan chain that installs a second Android app, Vwork, to create a work profile and drop a tampered banking app inside it. Work-profile isolation hides the trojan from the banking app’s malware checks on the personal profile. Confirmed on infected devices in Indonesia. Gigabud arrives as a sideloaded fake airline/tax/government app, demands Accessibility and overlay permissions, overlays fake logins and lock-screen capture, then drives taps via Accessibility under a black screen. Vwork is based on open-source Shelter but strips caller checks so other apps can create profiles, clone apps, and open them; setup is reduced to a single Chinese-language prompt. Order observed: Gigabud → Vwork within minutes → cloned banking app. Distinct from desk card mantax-otax-android-20260910. Primary: Group-IB; wire: The Hacker News (10 Sep 2026).
- Product
- Android (Gigabud RAT / Vwork work-profile helper)
- Versions
- n/a (malware; sideloaded outside Play)
- Exploited in Australia?
- unknown
- Patch to
- Avoid sideloaded “gov/airline/tax” APKs; deny Accessibility to untrusted apps; remove unknown work profiles; reset device if compromise suspected
Primary: Group-IB — Vwork app cloning / Gigabud (9 Sep 2026) · The Hacker News (10 Sep 2026)
