← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Gigabud Banking Trojan Uses Android Work Profiles to Evade Malware Detection

🔄 Updated 7h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Gigabud trojan installs a second app, Vwork, to create a work profile.
  • Tampered banking apps are placed within the work profile.
  • This technique evades banking app malware detection.
  • The trojan gains control via Accessibility access.

New Evasion Tactic for Gigabud Trojan

The Gigabud banking trojan has adopted a new technique to avoid detection by banking applications. According to a report by security firm Group-IB, the trojan now installs a secondary Android application that establishes a work profile on the compromised device. Within this isolated work profile, a modified banking application is then deployed.

Exploiting Android Work Profiles

Android work profiles are typically used by employers to separate work-related applications and data from personal content on a device. By leveraging this feature, the Gigabud trojan creates a barrier between its malicious components in the personal space and the banking app within the work profile. This separation prevents the banking app's built-in malware checks from detecting the trojan, allowing fraudulent transactions to proceed unnoticed by the user.

How the Trojan Operates

Gigabud, identified as a remote access trojan active since 2022 and linked to the GoldFactory group, initially infects devices through fake applications disguised as legitimate services like airlines or tax offices. Upon installation, it requests extensive permissions, including Accessibility access, which grants the operator full control. The trojan then identifies banking targets, overlays fake login screens to capture credentials, and can execute transactions while obscuring the activity with a black screen.

Vwork App Facilitates Isolation

The second application used by Gigabud to create and manage the work profile is named Vwork. Group-IB noted that Vwork's architecture resembles Shelter, an open-source tool that also utilizes work profiles for app isolation. However, unlike Shelter, which is manually controlled by the user, Vwork automates the setup of work profiles and the cloning of applications into them, enabling the trojan's stealthy operation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Sep 10

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub PeterCxy/Shelter

Reporting from

The Gigabud banking trojan now installs a second Android app to create a work profile on infected phones, then places a tampered banking app inside it. This method allows the trojan to bypass banking app malware checks, as the work profile separates its contents from the personal space where the trojan resides.