The Gigabud banking trojan has adopted a new technique to avoid detection by banking applications. According to a report by security firm Group-IB, the trojan now installs a secondary Android application that establishes a work profile on the compromised device. Within this isolated work profile, a modified banking application is then deployed.
Android work profiles are typically used by employers to separate work-related applications and data from personal content on a device. By leveraging this feature, the Gigabud trojan creates a barrier between its malicious components in the personal space and the banking app within the work profile. This separation prevents the banking app's built-in malware checks from detecting the trojan, allowing fraudulent transactions to proceed unnoticed by the user.
Gigabud, identified as a remote access trojan active since 2022 and linked to the GoldFactory group, initially infects devices through fake applications disguised as legitimate services like airlines or tax offices. Upon installation, it requests extensive permissions, including Accessibility access, which grants the operator full control. The trojan then identifies banking targets, overlays fake login screens to capture credentials, and can execute transactions while obscuring the activity with a black screen.
The second application used by Gigabud to create and manage the work profile is named Vwork. Group-IB noted that Vwork's architecture resembles Shelter, an open-source tool that also utilizes work profiles for app isolation. However, unlike Shelter, which is manually controlled by the user, Vwork automates the setup of work profiles and the cloning of applications into them, enabling the trojan's stealthy operation.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Gigabud banking trojan now installs a second Android app to create a work profile on infected phones, then places a tampered banking app inside it. This method allows the trojan to bypass banking app malware checks, as the work profile separates its contents from the personal space where the trojan resides.