THE Hacker News reports that the Gigabud banking trojan now drops a second Android app, named Vwork, which creates a work profile on an infected device. Group‑IB, in a September 9 briefing, explains that the work profile is a separate space Android uses for employer apps, and anything inside it is shielded from the banking app’s own malware checks.
On affected devices, the banking app’s security scans therefore cannot see the trojan sitting in the personal space, allowing fraudulent payments to proceed while appearing legitimate to the bank’s alerts.
Gigabud is a remote access trojan active since 2022 and linked to the GoldFactory operation. The campaign unfolds by installing a fake app outside official stores, upon first launch requesting Accessibility access, permission to draw over other apps, and background activity. The attacker then learns all installed apps, overlays a fake banking login screen to capture keystrokes, and uses a second, invisible overlay to hijack the device’s lock screen code.
Vwork’s architecture appears derived from Shelter, an open‑source container tool, but in Gigabud’s version it can be driven by other apps and external command servers, removing checks that previously prevented such actions. Group‑IB notes that Indonesia is the only country where a full infection chain has been confirmed; other regions show detected samples but not confirmed infections.
Group‑IB’s data for Indonesia between February and July 2026 cites about 1,469 compromised devices and 1,281 potentially compromised logins, with losses around $960,000. The firm stresses these figures reflect its observed activity and do not represent the full picture. The report advises users to install apps only from official stores, deny Accessibility access to non‑tool apps, and use a second banking factor not reliant on SMS.