Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

September 11, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Android mobile banking users
Incident: Deployment of the Gigabud banking trojan using Work Profile isolation to evade detection.
Impact: Unauthorized financial transactions and full remote device control.
Attacker: GoldFactory
Analysis: The Gigabud trojan, linked to the GoldFactory group, employs a secondary app called Vwork to create a separate Android Work Profile. By placing a tampered banking app within this isolated container, the malware hides itself from the banking app’s built-in malware scanners. Once established, the attackers use Accessibility services to remotely control the device and execute fraudulent transactions.
Recommendations: Avoid sideloading apps from unofficial sources or third-party portals.; Be extremely cautious when granting Accessibility services permissions to unknown apps.; Monitor device settings for the unauthorized creation of Work Profiles.
Source: The Hacker News / Group-IB

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *