RESEARCHERS have detailed how the Android banking Trojan Gigabud can undermine device security by creating a second work profile and running a cloned banking app inside it. Group-IB researchers found that Gigabud uses a malicious variant of Shelter, named Vwork, to modify the legitimate open‑source tool so it can be controlled remotely.
The operator clones a target banking app into the new work profile, enabling fraudulent transactions to be executed from that isolated environment while potentially evading cross‑profile detections.
Victims are typically drawn into sideloading fake airline, tax, or government apps via phishing, social media, or messages. Gigabud asks for Accessibility access, overlays to display fake login screens, and an exemption from battery optimisation, then identifies banking apps installed on the device. After stealing credentials and the device PIN through overlays, the operator installs Vwork to create the second profile, clone the banking app, and remotely perform transactions from the clone.
The tool is modified to remove cross‑profile protections, expose components for cloning and opening apps, and hide its launcher, making the fraud harder to link to malware elsewhere on the device. Malwarebytes lists several component detections for Gigabud, underscoring the need for cautious sideloading, scrutinising permissions, and keeping Android security software up to date. A suspicious second banking app instance should trigger particular concern, though work profiles alone are not proof of compromise.
If you have installed a suspicious APK and granted it special permissions, contact your bank and consider revoking permissions, uninstalling the app, and possibly performing a factory reset after safeguarding essential data.