THE Android banking trojan Gigabud has been enhanced to clone banking apps into a separate Android work profile, enabling fraudsters to dissociate a malware alert from subsequent transactions. Group-IB’s research, published on 9 September 2026, ties Gigabud to a weaponised fork of the Shelter cloning app, called Vwork, and attributes both to the GoldFactory group.
While infection chains were confirmed on devices in Indonesia, Gigabud samples designed to work with Vwork targeted 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand and Turkiye.
Vwork exploits Android’s Work Profile to place cloned banking apps in an isolated environment. The malware provides three new commands to provision the profile, clone a named app and report back what has been cloned, with cloning gated by a token retrieved from an external authorization server.
The strategy creates a “detection isolation” where apps in the work profile are largely invisible to signature-based detection in the personal profile, so a payment can appear to originate from an unrecognised device with no malware history. Operators then wait for the victim to initiate a transaction, present fake login screens to harvest credentials, while an invisible overlay captures the lock screen code; a black screen conceals the fraud in real time.
Group-IB’s Indonesian data (February–July 2026) pointed to about 1,469 compromised devices and 1,281 potentially compromised logins, with estimated losses around $960,939, describing the figures as indicative rather than definitive. Banks were advised to consider device binding and to rely on official app stores, while users are urged to be vigilant for work profiles appearing without user setup.