Skip to Content
Join the Network with Us — Join Membership


Hackers Clone Banking Apps into Hidden Profiles, Android Malware Raises New Fraud Concerns

September 10, 2026

Cybercriminals are deploying advanced Android malware that clones targeted banking applications inside hidden Work Profiles, allowing attackers to conduct unauthorised transactions while bypassing standard fraud detection systems. Security researchers have traced the operation to Gigabud, a Remote Access Trojan active since at least 2022, paired with Vwork, an application cloning utility based on the open-source software Shelter. The campaign tricks victims through phishing links on social media and messaging channels, into installing malicious files disguised as government, tax, or airline utilities, as well as fake financial services.

Exploiting Android Work Profiles to Evade Security Checks

Once granted device privileges, Gigabud seeks Accessibility permissions, overlay capabilities, and exemptions from battery optimisations, to capture screen credentials and remotely control the smartphone. The attack proceeds by deploying Vwork to establish an isolated Android Work Profile, inside which it duplicates the target banking application.

Because the operating system treats personal and enterprise workspaces as distinct environments, security signals triggered by malware in the personal space don't automatically transfer to the isolated setup. This division provides attackers with an environment that appears clean to security mechanisms during fraudulent transactions, a fairly clever exploitation of a legitimate feature.

Investigators confirmed instances where fake financial applications functioned from inside these isolated work environments, including documented activity in Indonesia. Vwork was also observed concealing its launcher icon, while accepting remote instructions from Gigabud to initiate setup, duplicate apps, and transmit inventory logs back to control servers.

Significant Financial Losses Recorded Across Global Targets

Monitoring between February and July 2026 uncovered roughly 1,469 compromised devices and 1,281 compromised account credentials in Indonesia alone, resulting in estimated losses of ₹8.2 crore. Analysts note that these numbers reflect only visible telemetry and point to a much broader international campaign linked to GoldFactory.

Compatible malware samples have been detected targeting users across Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Turkiye, and a member country of the Gulf Cooperation Council, indicating this is a fairly widespread, coordinated operation rather than an isolated regional threat. The findings demonstrate a coordinated strategy where cybercrime syndicates abuse legitimate device management features originally designed to separate professional and private phone usage.

Behavioural Safeguards Urged as Threat Tactics Evolve

Security professionals warn that unexplained Work Profile installations, duplicated banking apps, and irregular Accessibility requests serve as clear indicators of a compromised smartphone. Users are advised to avoid sideloading APK files received over private messages, and to limit sensitive permissions exclusively to verified programs obtained from official digital storefronts.

A researcher at Algoritha Security noted that detecting standalone malicious files is no longer sufficient to stop modern banking fraud. Financial institutions and payment networks must shift focus toward behavioural analysis, correlating recent profile creation, overlay activity, and unusual transaction parameters, to intercept unauthorised fund transfers before processing is even completed.

FAQs

Q1. How does the Gigabud and Vwork malware combination work?

Gigabud gains device access through Accessibility permissions and overlay capabilities, then deploys Vwork to create a hidden Android Work Profile where it clones the victim's banking app, allowing fraudulent transactions to appear separate from the security-monitored personal environment.

Q2. Which countries have been affected by this malware campaign?

Compatible malware samples have been detected targeting users across Indonesia, Brazil, Colombia, Egypt, Laos, Mexico, Morocco, the Philippines, Thailand, Turkiye, and a Gulf Cooperation Council member country.

Q3. What can users do to protect themselves from this type of malware?

Users are advised to avoid sideloading APK files received through private messages and to only install apps requesting sensitive permissions from official app stores like Google Play.

in News
Share this post
Archive