INDONESIA has emerged as an early testing ground for a novel Android banking malware technique that exploits Google's Work Profile to help fraudsters evade security controls. Group-IB researchers describe how the GoldFactory group uses the Gigabud Trojan to contaminate devices, gain a broad set of permissions, and then install a companion app called Vwork, a fork of the Shelter app-cloning tool.
Vwork leverages the Work Profile to clone an existing banking app into a separate, sandboxed space, allowing operators to conduct fraudulent transactions while a black screen hides the activity. The technique relies on Gigabud issuing commands via the Vwork-proxy arrangement, enabling live remote control of the victim’s device even after fraud signals have been triggered on the personal profile.
In Indonesia, the impact appears significant: Group-IB identified roughly 1,469 compromised devices and 1,281 potentially compromised logins between February and July, linked to nearly $1 million in losses. The campaign includes the discovery of Vwork alongside Gigabud infections, with a confirmed case involving a fake copy of an Indonesian bank’s app. The malware targets Android devices and has been active since 2022, used across Southeast Asia, the Middle East, Africa, and Latin America.
Analysts emphasise that the Indonesia-focused blend of a large mobile banking audience and widespread Android use makes it a particularly attractive target, and that the Work Profile evasion mechanism risks undermining traditional fraud signals and security tooling by isolating malicious activity within a separate profile. Group-IB notes practical warning signs, such as identical banking apps across profiles, unexpected app installations, and unnecessary accessibility permissions.